CVE-2026-23760Active Exploitation(smartertools / smartermail)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 6 mentions and remains active

Immediate actions

  • Patch smartertools smartermail systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts. An unauthenticated attacker can supply a target administrator username and a new password to reset the account, resulting in full administrative compromise of the SmarterMail instance. NOTE: SmarterMail system administrator privileges grant the ability to execute operating system commands via built-in management functionality, effectively providing administrative (SYSTEM or root) access on the underlying host.

8.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-02-16. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-288

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • smartermail

Threat summary

  • Active exploitation appears in 48 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 60 mentions across 25 observed days

What's happening

  • Active exploitation reported across 48 signals
  • Exploit tool or code specified in 3 signals
  • PoC mentioned or linked in 7 signals
  • Patch or workaround mentioned in 24 signals
  • Technical details provided in 34 signals
  • General: 5 classified signals
  • Peaked 15d ago at 6 mentions (2026-02-10); latest day: 1
  • 60 total mentions across 25 days

Affected systems

Products
smartermail

Deep dive

Activity timeline60 mentions / 25d
02356Mentions · 2026-01-27: 4Mentions · 2026-01-28: 3Mentions · 2026-01-29: 1Mentions · 2026-01-30: 2Mentions · 2026-01-31: 1Mentions · 2026-02-03: 2Mentions · 2026-02-05: 2Mentions · 2026-02-06: 1Mentions · 2026-02-09: 5Mentions · 2026-02-10: 6Mentions · 2026-02-11: 3Mentions · 2026-02-12: 3Mentions · 2026-02-13: 4Mentions · 2026-02-14: 1Mentions · 2026-02-18: 4Mentions · 2026-02-19: 2Mentions · 2026-02-25: 1Mentions · 2026-03-04: 2Mentions · 2026-03-23: 1Mentions · 2026-04-06: 4Mentions · 2026-04-07: 3Mentions · 2026-04-18: 1Mentions · 2026-05-04: 1Mentions · 2026-05-08: 2Mentions · 2026-08-19: 1PoC Mentioned / Linked · 2026-01-31: 1PoC Mentioned / Linked · 2026-02-18: 4PoC Mentioned / Linked · 2026-02-19: 1PoC Mentioned / Linked · 2026-05-08: 1Exploit Tool / Code · 2026-02-10: 1Exploit Tool / Code · 2026-02-18: 1Exploit Tool / Code · 2026-02-25: 1Active Exploitation · 2026-01-27: 3Active Exploitation · 2026-01-28: 1Active Exploitation · 2026-01-29: 1Active Exploitation · 2026-01-30: 2Active Exploitation · 2026-01-31: 1Active Exploitation · 2026-02-03: 2Active Exploitation · 2026-02-05: 1Active Exploitation · 2026-02-06: 1Active Exploitation · 2026-02-09: 4Active Exploitation · 2026-02-10: 6Active Exploitation · 2026-02-11: 2Active Exploitation · 2026-02-12: 2Active Exploitation · 2026-02-13: 4Active Exploitation · 2026-02-14: 1Active Exploitation · 2026-02-18: 4Active Exploitation · 2026-02-19: 1Active Exploitation · 2026-02-25: 1Active Exploitation · 2026-03-23: 1Active Exploitation · 2026-04-06: 4Active Exploitation · 2026-04-07: 2Active Exploitation · 2026-04-18: 1Active Exploitation · 2026-05-08: 2Active Exploitation · 2026-08-19: 1Patch / Workaround · 2026-01-27: 2Patch / Workaround · 2026-01-28: 2Patch / Workaround · 2026-01-30: 2Patch / Workaround · 2026-01-31: 1Patch / Workaround · 2026-02-05: 1Patch / Workaround · 2026-02-09: 1Patch / Workaround · 2026-02-10: 3Patch / Workaround · 2026-02-11: 1Patch / Workaround · 2026-02-12: 2Patch / Workaround · 2026-02-13: 2Patch / Workaround · 2026-02-14: 1Patch / Workaround · 2026-02-18: 1Patch / Workaround · 2026-03-04: 1Patch / Workaround · 2026-04-06: 2Patch / Workaround · 2026-04-07: 1Patch / Workaround · 2026-05-08: 1Technical Details · 2026-01-27: 3Technical Details · 2026-01-28: 3Technical Details · 2026-01-29: 1Technical Details · 2026-01-30: 2Technical Details · 2026-01-31: 1Technical Details · 2026-02-03: 1Technical Details · 2026-02-05: 1Technical Details · 2026-02-06: 1Technical Details · 2026-02-09: 3Technical Details · 2026-02-10: 4Technical Details · 2026-02-11: 1Technical Details · 2026-02-12: 2Technical Details · 2026-02-13: 1Technical Details · 2026-02-14: 1Technical Details · 2026-02-18: 1Technical Details · 2026-02-19: 1Technical Details · 2026-02-25: 1Technical Details · 2026-03-04: 2Technical Details · 2026-03-23: 1Technical Details · 2026-04-06: 1Technical Details · 2026-04-07: 1Technical Details · 2026-05-04: 101-2701-2901-3102-0502-0902-1102-1302-1802-2503-2304-0705-0408-19
Signal classification5 categories
Active Exploitation
4575.0%
Patch
58.3%
General
58.3%
Disclosure
35.0%
Exploit
23.3%
Referenced assets78 URLs
By indicator
Classification over time
DateTotalLabels
2026-01-274
Active Exploitation3Disclosure1
2026-01-283
Active Exploitation1Disclosure1Patch1
2026-01-291
Active Exploitation1
2026-01-302
Patch2
2026-01-311
Active Exploitation1
2026-02-032
Active Exploitation2
2026-02-052
Active Exploitation1General1
2026-02-061
Active Exploitation1
2026-02-095
Active Exploitation4General1
2026-02-106
Active Exploitation6
2026-02-113
Active Exploitation2General1
2026-02-123
Active Exploitation2General1
2026-02-134
Active Exploitation4
2026-02-141
Active Exploitation1
2026-02-184
Active Exploitation4
2026-02-192
Disclosure1Exploit1
2026-02-251
Active Exploitation1
2026-03-042
General1Patch1
2026-03-231
Active Exploitation1
2026-04-064
Active Exploitation4
2026-04-073
Active Exploitation2Patch1
2026-04-181
Active Exploitation1
2026-05-041
Exploit1
2026-05-082
Active Exploitation2
2026-08-191
Active Exploitation1
Full discourse20 posts
  • blackorbird@blackorbird
    Active Exploitation

    Storm-2603 Exploits CVE-2026-23760 to Stage Warlock Ransomware https://reliaquest.com/blog/threat-spotlight-storm-2603-exploits-CVE-2026-23760-to-stage-warlock-ransomware https://t.co/cbnL3sBQAR

    Post summary

    The threat group Storm-2603 is actively exploiting CVE-2026-23760 to deploy Warlock ransomware, as highlighted in the referenced blog post.

    1901952.7K
    39.9K followersView on X
  • Censys@censysio
    Active Exploitation

    🚨 CVE-2026-23760 (SmarterMail): Critical (CVSS 9.3) authentication bypass vulnerability in SmarterTools’ SmarterMail software. Successful exploitation results in complete administrative compromise with system-level access on the underlying host. ⚠️ Actively exploited in the wild. 🛠️ Patch status: Fixed in build 9511 (and later). 👉 Full advisory: https://hubs.ly/Q040B6qD0 #cve202623760 #infosec #smartermail #smartertools

    Post summary

    CVE‑2026‑23760 is a critical authentication bypass in SmarterMail, actively exploited in the wild, but has been patched in build 9511.

    0711952.5K
    11.9K followersView on X
  • 780th Military Intelligence Brigade (Cyber)@780thC
    Active Exploitation

    Storm-2603 Exploits CVE-2026-23760 to Stage Warlock Ransomware "This appears to be the first observed exploitation linking the China-based actor to the vulnerability as an entry point for its “Warlock” ransomware operations." @ReliaQuest Threat Research https://reliaquest.com/blog/threat-spotlight-storm-2603-exploits-CVE-2026-23760-to-stage-warlock-ransomware

    Post summary

    The blog reports the first real‑world exploitation of CVE-2026-23760 by Storm-2603, linking the vulnerability to Warlock ransomware operations, but offers no PoC, patch, or technical details.

    031112929
    34.4K followersView on X
  • Cloudforce One@Cloudforce_One
    Patch

    Cloudflare has released new WAF rules addressing the following CVEs to enhance customer protection. SmarterMail - Arbitrary File Upload (CVE-2025-52691) SmarterMail - Authentication Bypass (CVE-2026-23760) https://developers.cloudflare.com/changelog/post/2026-03-02-waf-release/

    Post summary

    Cloudflare announced new WAF rules that mitigate two SmarterMail CVEs, providing a protective patch for customers.

    1301021.9K
    3.0K followersView on X
  • Crowdfense@crowdfense
    Disclosure

    The following vulnerabilities have been added to our feed: - CVE-2025-49113: Roundcube PHP Object Deserialization RCE - CVE-2025-52691: SmarterMail Arbitrary File Upload RCE - CVE-2026-23760: SmarterMail Authentication Bypass RCE https://www.crowdfense.com/n-day-feed/

    Post summary

    The feed announces the addition of three new RCE vulnerabilities affecting Roundcube and SmarterMail, providing brief high-level descriptions but no detailed technical analysis or mitigation information.

    11055772
    2.9K followersView on X
  • Cyber_OSINT@Cyber_O51NT
    Active Exploitation

    ReliaQuest identified Storm-2603 exploiting CVE-2026-23760 to bypass SmarterMail authentication, staging Warlock ransomware by abusing Volume Mount and deploying Velociraptor; defenders should upgrade to Build 9511 and isolate mail servers. https://reliaquest.com/blog/threat-spotlight-storm-2603-exploits-CVE-2026-23760-to-stage-warlock-ransomware

    Post summary

    Storm‑2603 is actively exploiting CVE‑2026‑23760 to bypass SmarterMail authentication and stage Warlock ransomware, with defenders advised to upgrade to Build 9511 and isolate mail servers.

    04051888
    21.3K followersView on X
  • ReliaQuest@ReliaQuest
    Active Exploitation

    🚨 The ReliaQuest threat research identified exploitation of SmarterMail vulnerability CVE-2026-23760 potentially linked to Storm-2603, a China-based actor behind Warlock ransomware. Threat actors bypass authentication to reset admin passwords, then use legitimate tools like Velociraptor to maintain persistent access. CISA also warned of exploitation of another SmarterMail vulnerability (CVE-2026-24423), and we've observed possible attempts originating from different infrastructure. 👉 Read more: https://reliaquest.com/blog/threat-spotlight-storm-2603-exploits-CVE-2026-23760-to-stage-warlock-ransomware #ReliaQuest #MakeSecurityPossible #ThreatResearch

    Post summary

    ReliaQuest reports that CVE‑2026‑23760 is being actively exploited by Storm‑2603, with attackers bypassing authentication to reset admin passwords and using Velociraptor for persistence.

    020701.1K
    2.5K followersView on X
  • Chukwuemeka@chukwuemekaoa
    Active Exploitation

    5 breaches making headlines: 1. Warlock ransomware hit SmarterTools via unpatched SmarterMail (CVE-2026-23760) 2. China-linked UNC3886 targeting Singapore telecom with zero-days 3. Microsoft Windows Shell zero-day (CVE-2026-21510) actively exploited databreach. 1/2

    Post summary

    The post highlights that CVE-2026-21510, a Windows Shell zero‑day, is actively exploited, while also noting a Warlock ransomware attack via an unpatched SmarterMail.

    11020186
    344 followersView on X
  • Gray Hats@the_yellow_fall
    Active Exploitation

    Storm-2603 exploits SmarterMail vulnerability CVE-2026-23760 to deploy Warlock ransomware. Upgrade to Build 9511 immediately to prevent system compromise. #SmarterMail #Ransomware #Storm2603 #CyberSecurity #CVE202623760 #InfoSec #Warlock https://securityonline.info/email-under-siege-storm-2603-exploits-smartermail-to-deploy-warlock-ransomware/

    Post summary

    Storm-2603 is actively exploiting the SmarterMail CVE-2026-23760 vulnerability to deploy Warlock ransomware, and users are urged to upgrade to Build 9511 to mitigate the threat.

    00030381
    10.4K followersView on X
  • SC Media@SCMagazine
    Active Exploitation

    #Ransomware crews are exploiting @SmarterTools' SmarterMail bugs for unauth RCE + admin takeover (CVE-2026-24423, CVE-2026-23760), reported @ReliaQuest. Patch to Build 9511 and isolate mail servers ASAP. #cybersecurity #infosec #CISO #ITsecurity https://bit.ly/3MwftJs

    Post summary

    Ransomware crews are actively exploiting two SmarterMail CVEs—unauthenticated RCE and admin takeover—requiring an immediate patch to Build 9511 and isolation of mail servers.

    01020351
    119.3K followersView on X
  • Red Secure Tech Ltd.@redsecuretech
    Exploit

    CVE-2026-23760 SmarterMail exploit lets attackers reset admin passwords via an unauthenticated API call. https://www.redsecuretech.co.uk/blog/post/cve-2026-23760-smartermail-exploit-admin-reset-attack/1152 #SmarterMail #InfoSec #CyberSecurity #AuthenticationBypass #EmailServerSecurity #Ransomware #PatchNow #CriticalVulnerability #SystemAdministration https://t.co/NyCycu6opa

    Post summary

    The CVE exposes an authentication bypass via an unauthenticated API that allows admin password reset; the post details the issue but lacks evidence of active exploitation, patch, or PoC code.

    0101047
    48 followersView on X
  • SC Media@SCMagazine
    Active Exploitation

    #Ransomware crews are exploiting @SmarterTools' SmarterMail bugs for unauth RCE + admin takeover (CVE-2026-24423, CVE-2026-23760), reported @ReliaQuest. Patch to Build 9511 and isolate mail servers ASAP. #cybersecurity #infosec #CISO #ITsecurity https://bit.ly/3MwftJs

    Post summary

    Ransomware groups are actively exploiting unauthenticated remote code execution and admin takeover in SmarterMail, as reported by ReliaQuest, and the vendor recommends applying Build 9511 patch and isolating mail servers immediately.

    01001419
    119.3K followersView on X
  • CyberM3k@cyber_mek
    Active Exploitation

    5 breaches making headlines: 1. Warlock ransomware hit SmarterTools via unpatched SmarterMail (CVE-2026-23760) 2. China-linked UNC3886 targeting Singapore telecom with zero-days 3. Microsoft Windows Shell zero-day (CVE-2026-21510) actively exploited

    Post summary

    The post highlights recent breaches, noting that the Microsoft Windows Shell zero‑day (CVE‑2026‑21510) is being actively exploited in the wild.

    1001055
    10 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-20841 2 - CVE-2026-23760 3 - CVE-2026-21508 4 - CVE-2024-27834 5 - CVE-2026-21514 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post merely lists five trending CVEs without any technical details, exploitation evidence, or patch information.

    00020190
    1.7K followersView on X
  • SC Media@SCMagazine
    Active Exploitation

    #Ransomware crews are exploiting @SmarterTools' SmarterMail bugs for unauth RCE + admin takeover (CVE-2026-24423, CVE-2026-23760), reported @ReliaQuest. Patch to Build 9511 and isolate mail servers ASAP. #cybersecurity #infosec #CISO #ITsecurity https://bit.ly/3MwftJs

    Post summary

    Ransomware groups are actively exploiting unauthenticated remote code execution in SmarterMail, prompting an immediate patch to Build 9511 and isolation of mail servers.

    100101.1K
    119.3K followersView on X
  • Threat Intelligence@threatintel
    General

    #ThreatProtection #CVE-2026-23760 - #SmarterTools #SmarterMail #vulnerability, read more about Symantec's protection: https://www.broadcom.com/support/security-center/protection-bulletin/cve-2026-23760-smartertools-smartermail-vulnerability

    Post summary

    The tweet references CVE‑2026‑23760 and links to a protection bulletin, but provides no technical details, PoC, exploitation evidence, or patch information.

    01010983
    114.2K followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    00:00 UTC: CVE-2026-23760 disclosed. CISA: CVE-2026-23760 added to Known Exploited Vulnerabilities — SmarterTools SmarterMail Status: ✅ Confirmed exploited in the wild Date added: 2026-01-26 Required action: Apply mitigations per vendor instructions, follow applicable…

    Post summary

    CVE-2026-23760 is confirmed to be actively exploited in the wild, and users should apply vendor‑issued mitigations.

    1000040
    186 followersView on X
  • White Rabbitx@TheRabbitPy
    Active Exploitation

    🚨 CVE-2026-23760 (CVSS 9.8): SmarterMail <9511 auth bypass in password reset API → unauth account takeover. Email servers compromised!

    Post summary

    CVE‑2026‑23760, a high‑severity authentication bypass in SmarterMail’s password reset API, is actively being exploited, enabling unauthenticated account takeover and having compromised multiple email servers.

    0001079
    395 followersView on X
  • Arnav Sharma 🇦🇺@arnavsharma
    Active Exploitation

    Rapid weaponization: After disclosure, underground Telegrams spread SmarterMail PoCs and stolen admin creds within days, fueling CVE-2026-24423 and CVE-2026-23760 ransomware activity. Monitor these crypto-locked forums to anticipate threats. #Cybersecuri… https://ift.tt/q5x7rDA

    Post summary

    After disclosure, underground forums rapidly spread SmarterMail PoCs and stolen admin credentials, leading to active exploitation of CVE-2026-24423 and CVE-2026-23760 in ransomware attacks.

    0000158
    2.3K followersView on X
  • RST Cloud@rst_cloud
    Active Exploitation

    #threatreport #LowCompleteness Storm-2603 Exploits CVE-2026-23760 to Stage Warlock Ransomware | 10-02-2026 Source: https://reliaquest.com/blog/threat-spotlight-storm-2603-exploits-CVE-2026-23760-to-stage-warlock-ransomware/ Key details below ↓ 🧑‍💻Actors/Campaigns: Storm-2603 💀Threats: X2anylock, Lolbin_technique, Blackbasta, 🎯Victims: Email service providers, Organizations using smartermail 🌐Geo: China 🔓CVEs: CVE-2026-23760 \[[Vulners](https://vulners.com/cve/CVE-2026-23760)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - smartertools smartermail (<100.0.9511) CVE-2026-24423 \[[Vulners](https://vulners.com/cve/CVE-2026-24423)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - smartertools smartermail (<100.0.9511) 📚TTPs: ⚔️Tactics: 3 🛠️Technics: 0 🤖LLM extracted TTPs:` T1036, T1071.001, T1102, T1105, T1190, T1218.007, T1569.002 🧨IOCs: - File: 3 - Domain: 3 - IP: 5 💽Software: Velociraptor, Windows Installer, Supabase 🔠Functions: ConnectToHub #threatreport: The threat actor group known as Storm-2603 has been identified utilizing the vulnerability CVE-2026-23760 to stage the deployment of Warlock ransomware. This vulnerability, present in SmarterMail, allows attackers to bypass authentication through a flaw in the password reset API, where the system fails to properly validate the old password. Consequently, attackers can reset the administrator password without authentication. To mitigate this threat, organizations are advised to upgrade to SmarterMail Build 9511 or later and isolate mail servers to prevent lateral movement. The initial attack phase begins with the exploitation of the aforementioned vulnerability. After gaining access to the mail server, the attackers leverage a feature within SmarterMail that permits volume mounting to gain control over the underlying Windows server, thus enabling them to execute arbitrary code. This execution is facilitated by the use of legitimate Windows Installer functions to download a malicious payload labeled as v4.msi from Supabase, a cloud service, which is intended to install Velociraptor—a legitimate forensic tool that the attackers will use for command-and-control (C2) operations while blending in with normal administrative activities. Continuing through the cyber kill chain, once remote code execution (RCE) is achieved, the use of Velociraptor establishes a persistent backdoor for further actions, likely culminating in the deployment of the Warlock ransomware. The behavior of Storm-2603 demonstrates a sophisticated approach that utilizes legitimate tools and administrative capabilities to evade detection. Additionally, there is evidence of concurrent exploitation efforts associated with CVE-2026-24423, indicating that multiple threat actors may be targeting similar systems. It is crucial for organizations to act decisively by patching both identified vulnerabilities and implementing protections against lateral movements and command-and-control communications. Notably, the speed with which Storm-2603 can exploit these vulnerabilities suggests a limited response window for organizations, emphasizing the importance of proactive measures. Critical to defending against this type of attack is the ability to detect unusual activity from legitimate processes—specifically monitoring msiexec activity and unauthorized connections during the staging phase. Such preventive measures can significantly hinder or disrupt ransomware deployment efforts before they escalate.

    Post summary

    The report documents active exploitation by Storm‑2603 of CVE‑2026‑23760 to deploy Warlock ransomware, detailing the vulnerability mechanism and urging immediate patching and mitigation steps.

    0000189
    586 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsmartertoolssmartermail---

Explore more