CVE-2026-24423Active Exploitation(smartertools / smartermail)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 30 mentions and remains active

Immediate actions

  • Patch smartertools smartermail systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the SmarterMail to the malicious HTTP server, which serves the malicious OS command. This command will be executed by the vulnerable application.

8.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-02-26. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-306

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • smartermail

Threat summary

  • Active exploitation appears in 65 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 98 mentions across 26 observed days

What's happening

  • Active exploitation reported across 65 signals
  • Exploit tool or code specified in 3 signals
  • PoC mentioned or linked in 8 signals
  • Patch or workaround mentioned in 44 signals
  • Technical details provided in 70 signals
  • Disclosure: 12 classified signals
  • Peaked 19d ago at 30 mentions (2026-02-06); latest day: 2
  • 98 total mentions across 26 days

Affected systems

Products
smartermail

Deep dive

Activity timeline98 mentions / 26d
08152330Mentions · 2026-01-28: 3Mentions · 2026-01-30: 7Mentions · 2026-01-31: 2Mentions · 2026-02-01: 3Mentions · 2026-02-04: 1Mentions · 2026-02-05: 3Mentions · 2026-02-06: 30Mentions · 2026-02-07: 6Mentions · 2026-02-08: 5Mentions · 2026-02-09: 4Mentions · 2026-02-10: 6Mentions · 2026-02-11: 4Mentions · 2026-02-12: 2Mentions · 2026-02-13: 3Mentions · 2026-02-14: 2Mentions · 2026-02-18: 5Mentions · 2026-02-19: 1Mentions · 2026-02-25: 1Mentions · 2026-02-26: 1Mentions · 2026-02-27: 1Mentions · 2026-02-28: 2Mentions · 2026-03-23: 1Mentions · 2026-03-24: 1Mentions · 2026-03-26: 1Mentions · 2026-04-17: 1Mentions · 2026-05-08: 2PoC Mentioned / Linked · 2026-01-28: 1PoC Mentioned / Linked · 2026-02-06: 1PoC Mentioned / Linked · 2026-02-10: 1PoC Mentioned / Linked · 2026-02-18: 4PoC Mentioned / Linked · 2026-02-19: 1Exploit Tool / Code · 2026-02-18: 1Exploit Tool / Code · 2026-02-19: 1Exploit Tool / Code · 2026-02-25: 1Active Exploitation · 2026-01-28: 1Active Exploitation · 2026-01-30: 1Active Exploitation · 2026-02-01: 1Active Exploitation · 2026-02-05: 2Active Exploitation · 2026-02-06: 24Active Exploitation · 2026-02-07: 4Active Exploitation · 2026-02-08: 5Active Exploitation · 2026-02-09: 3Active Exploitation · 2026-02-10: 6Active Exploitation · 2026-02-11: 1Active Exploitation · 2026-02-12: 2Active Exploitation · 2026-02-13: 3Active Exploitation · 2026-02-14: 2Active Exploitation · 2026-02-18: 4Active Exploitation · 2026-02-19: 1Active Exploitation · 2026-02-25: 1Active Exploitation · 2026-03-23: 1Active Exploitation · 2026-03-24: 1Active Exploitation · 2026-03-26: 1Active Exploitation · 2026-05-08: 1Patch / Workaround · 2026-01-28: 1Patch / Workaround · 2026-01-30: 7Patch / Workaround · 2026-02-01: 3Patch / Workaround · 2026-02-04: 1Patch / Workaround · 2026-02-05: 1Patch / Workaround · 2026-02-06: 16Patch / Workaround · 2026-02-07: 3Patch / Workaround · 2026-02-08: 1Patch / Workaround · 2026-02-10: 2Patch / Workaround · 2026-02-11: 2Patch / Workaround · 2026-02-12: 2Patch / Workaround · 2026-02-13: 2Patch / Workaround · 2026-02-14: 1Patch / Workaround · 2026-02-18: 1Patch / Workaround · 2026-03-23: 1Technical Details · 2026-01-28: 2Technical Details · 2026-01-30: 7Technical Details · 2026-01-31: 1Technical Details · 2026-02-01: 3Technical Details · 2026-02-04: 1Technical Details · 2026-02-05: 2Technical Details · 2026-02-06: 20Technical Details · 2026-02-07: 4Technical Details · 2026-02-08: 4Technical Details · 2026-02-09: 1Technical Details · 2026-02-10: 6Technical Details · 2026-02-11: 4Technical Details · 2026-02-12: 2Technical Details · 2026-02-13: 3Technical Details · 2026-02-14: 1Technical Details · 2026-02-18: 2Technical Details · 2026-02-25: 1Technical Details · 2026-02-26: 1Technical Details · 2026-03-23: 1Technical Details · 2026-03-24: 1Technical Details · 2026-03-26: 1Technical Details · 2026-04-17: 1Technical Details · 2026-05-08: 101-2801-3102-0402-0602-0802-1002-1202-1402-1902-2602-2803-2404-1705-08
Signal classification4 categories
Active Exploitation
6162.2%
Patch
1717.3%
Disclosure
1212.2%
General
88.2%
Referenced assets90 URLs
By indicator
Classification over time
DateTotalLabels
2026-01-283
Active Exploitation1Disclosure1General1
2026-01-307
Patch7
2026-01-312
Disclosure1General1
2026-02-013
Patch3
2026-02-041
Patch1
2026-02-053
Active Exploitation2Disclosure1
2026-02-0630
Active Exploitation23Disclosure2General2Patch3
2026-02-076
Active Exploitation3General1Patch2
2026-02-085
Active Exploitation5
2026-02-094
Active Exploitation3Disclosure1
2026-02-106
Active Exploitation6
2026-02-114
Active Exploitation1Disclosure2Patch1
2026-02-122
Active Exploitation2
2026-02-133
Active Exploitation3
2026-02-142
Active Exploitation2
2026-02-185
Active Exploitation4Disclosure1
2026-02-191
Active Exploitation1
2026-02-251
Active Exploitation1
2026-02-261
Disclosure1
2026-02-271
General1
2026-02-282
General2
2026-03-231
Active Exploitation1
2026-03-241
Active Exploitation1
2026-03-261
Active Exploitation1
2026-04-171
Disclosure1
2026-05-082
Active Exploitation1Disclosure1
Full discourse20 posts
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️ We added React Native community CLI vulnerability CVE-2025-11953 & SmarterTools SmarterMail vulnerability CVE-2026-24423 to our Known Exploited Vulnerabilities Catalog. Visit https://go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity https://t.co/rBMaOkPRwE

    Post summary

    The DHS has added CVE-2025-11953 and CVE-2026-24423 to its Known Exploited Vulnerabilities Catalog, indicating these vulnerabilities are being actively exploited, and it recommends applying mitigations.

    421058118.6K
    291.8K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    🚨 UPDATE: CISA adds SmarterMail RCE (CVE-2026-24423) to KEV after confirming ransomware exploitation in the wild. Unauthenticated attackers can run commands via the ConnectToHub API. Federal agencies must patch by Feb 26. 🔗 Full update → https://thehackernews.com/2026/01/smartermail-fixes-critical.html#flaw-exploited-in-ransomware-attacks https://t.co/MHEbWojade

    Post summary

    CISA confirms active ransomware exploitation of SmarterMail RCE (CVE-2026-24423) in the wild and urges federal agencies to patch by Feb 26.

    316162118.3K
    1.0M followersView on X
  • The Hacker News@TheHackersNews
    Patch

    ⚠️ SmarterMail fixed a critical unauthenticated RCE in its email server software. The flaw, CVE-2026-24423 (CVSS 9.3), lets attackers execute OS commands via a crafted remote server. It affects builds before 9511. 🔗 Fixed builds and attack mechanics → https://thehackernews.com/2026/01/smartermail-fixes-critical.html

    Post summary

    SmarterMail has released a fix for CVE‑2026‑24423, a critical remote‑code‑execution flaw affecting versions before build 9511, and provides details on the vulnerability and its resolution.

    21014247.4K
    1.0M followersView on X
  • Crowdfense@crowdfense
    Disclosure

    The following weaponized vulnerabilities have been added to our n-day feed: - CVE-2025-61882: Oracle EBS - RCE - CVE-2026-24423: SmarterMail - RCE - CVE-2026-20941: Host Process - LPE - 0DAY-2026-0001: Visual Studio - Info Disclosure https://www.crowdfense.com/n-day-feed/

    Post summary

    The feed announces newly added vulnerabilities with basic type information but provides no details on exploitation, patches, or PoC.

    06029102.0K
    2.9K followersView on X
  • ZoomEye@zoomeye_team
    Disclosure

    🚨 CVE-2026-24423: SmarterMail Web Interface Remote Code Execution (RCE) Critical Unauthenticated RCE! By sending maliciously crafted HTTP requests targeting the login or API endpoints, remote attackers can execute arbitrary code without any authentication. This allows full compromise of the SmarterMail server and sensitive data. 📖 Full Vulnerability Details & Analysis at DarkEye: 👉https://www.darkeye.org/vuln/cve/CVE-2026-24423 🔍 Identify Targets via ZoomEye: Filter: vul.cve="CVE-2026-24423" Search Dork: app="SmarterMail" Exposure: 6k+ exposed instances identified globally. 👉 ZoomEye Search Link: https://www.zoomeye.ai/searchResult?q=dnVsLmN2ZT0iQ1ZFLTIwMjYtMjQ0MjMi&utm_source=twitter&utm_medium=social&utm_campaign=cve_ops_20260211 #SmarterMail #Infosec #CyberSecurity #DarkEye #RCE #BugBounty

    Post summary

    The tweet announces a newly disclosed unauthenticated RCE vulnerability in SmarterMail (CVE‑2026‑24423) with detailed technical information but no PoC, exploit code, active exploitation, or patch updates.

    21001972.7K
    11.9K followersView on X
  • Dark Web Informer@DarkWebInformer
    Active Exploitation

    ‼️ CISA has added two vulnerabilities to the KEV Catalog https://darkwebinformer.com/cisa-kev-catalog/ CVE-2026-24423: SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability: SmarterTools SmarterMail contains a missing authentication for critical function vulnerability in the ConnectToHub API method. This could allow the attacker to point the SmarterMail instance to a malicious HTTP server which serves the malicious OS command and could lead to command execution. CVE-2025-11953: React Native Community CLI OS Command Injection Vulnerability: React Native Community CLI contains an OS command injection vulnerability which could allow unauthenticated network attackers to send POST requests to the Metro Development Server and run arbitrary executables via a vulnerable endpoint exposed by the server. On Windows, attackers can also execute arbitrary shell commands with fully controlled arguments.

    Post summary

    CISA has listed two vulnerabilities in its KEV catalog, confirming active exploitation, but the post offers no PoC, exploit code, patch information, or false‑positive claim.

    0501553.7K
    164.9K followersView on X
  • Caitlin Condon@catc0n
    Active Exploitation

    The VulnCheck research team found an unauth RCE vuln in SmarterMail that at least three other researchers discovered independently. VulnCheck canaries are also detecting in-the-wild exploitation of CVE-2026-24423. https://www.vulncheck.com/blog/smartermail-connecttohub-rce-cve-2026-24423

    Post summary

    VulnCheck reports an unauthenticated RCE in SmarterMail (CVE‑2026‑24423) and notes that canary systems are detecting real‑world exploitation.

    060521.4K
    3.5K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(2/5追加) 🛡️No.1507 CVE-2025-11953 React Native Community CLI OS Command Injection Vulnerability ============= CVSSスコア: 9.8 (Base) / JFrog CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 種別:OSコマンドインジェクション (CWE-78 / JFrog) 深刻度:深刻🔥 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、リモートからMetro 開発サーバーに 細工されたPOST リクエストを送信することで、任意のファイルを実行される恐れがあります。Windows では、攻撃者は完全に制御された引数を使用して任意のシェルコマンドを実行される恐れがあります。 この脆弱性はランサムウェア事案での悪用が確認されています。 https://github.com/react-native-community/cli/commit/15089907d1f1301b22c72d7f68846a2ef20df547 https://github.com/react-native-community/cli/pull/2735 🛡️No.1508 CVE-2026-24423 SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability ============= CVSSスコア: 9.3 (Base) / VulnCheck CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N 種別:重要な機能に対する認証の欠如 (CWE-306 / VulnCheck) 深刻度:深刻🔥 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、SmarterMail インスタンスを悪意のある HTTP サーバーに誘導し、OS コマンドを実行される恐れがあります。 https://www.smartertools.com/smartermail/release-notes/current CISA Adds Two Known Exploited Vulnerabilities to Catalog | CISA https://www.cisa.gov/news-events/alerts/2026/02/05/cisa-adds-two-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    CISA added CVE-2025-11953 and CVE-2026-24423 to its catalog after confirming active exploitation, especially in ransomware cases, though no patch or exploit tool is disclosed.

    010904.2K
    42.5K followersView on X
  • ReliaQuest@ReliaQuest
    Active Exploitation

    🚨 The ReliaQuest threat research identified exploitation of SmarterMail vulnerability CVE-2026-23760 potentially linked to Storm-2603, a China-based actor behind Warlock ransomware. Threat actors bypass authentication to reset admin passwords, then use legitimate tools like Velociraptor to maintain persistent access. CISA also warned of exploitation of another SmarterMail vulnerability (CVE-2026-24423), and we've observed possible attempts originating from different infrastructure. 👉 Read more: https://reliaquest.com/blog/threat-spotlight-storm-2603-exploits-CVE-2026-23760-to-stage-warlock-ransomware #ReliaQuest #MakeSecurityPossible #ThreatResearch

    Post summary

    ReliaQuest reports active exploitation of SmarterMail CVE‑2026‑23760 by the Storm‑2603 actor, using authentication bypass to reset passwords and maintain persistence; possible attempts against CVE‑2026‑24423 are also noted.

    020701.1K
    2.5K followersView on X
  • 404🌐LABS@404LABSx
    Patch

    🚨 THREAT ALERT - Feb 6 🔥 CRITICAL: • 100+ new malware URLs • Emotet/QakBot C2s active • SmarterMail RCE (CVE-2026-24423) • Fortinet SSO bypass ⚠️ PATCH NOW! #ThreatIntel #Cybersecurity

    Post summary

    Threat alert warns of a new SmarterMail RCE (CVE‑2026‑24423) and urges immediate patching; no PoC, exploit code, or active exploitation evidence is provided.

    0303084
    48 followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-24423 - critical 🚨 SmarterMail - Remote Code Execution > SmarterTools SmarterMail < build 9511 contains an unauthenticated remote code executi... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-24423 @pdnuclei #NucleiTemplates #cve

    Post summary

    A critical unauthenticated RCE flaw (CVE‑2026‑24423) has been disclosed for SmarterMail build 9511, with a reference link but no PoC, exploit code, or patch information provided.

    01013166
    930 followersView on X
  • The Cyber Security Hub™@TheCyberSecHub
    Active Exploitation

    Ransomware attackers are exploiting critical SmarterMail vulnerability (CVE-2026-24423) https://www.helpnetsecurity.com/2026/02/06/ransomware-smartermail-cve-2026-24423/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The post states that ransomware actors are actively exploiting the critical CVE‑2026‑24423 in SmarterMail, but it provides no PoC, exploit code, patch details, or technical specifics.

    03020549
    192.8K followersView on X
  • DarkEye@darkeye_team
    Disclosure

    🚨 Detailed Analysis for CVE-2026-24423 (SmarterMail Remote Code Execution) Stop guessing the risk. The technical details are ready. 🔥 $5 Special Trial to celebrate our CVE Feed launch! Get the Analysis & Prioritized Asset List now: https://www.darkeye.org/vuln/cve/CVE-2026-24423 Critical Unauthenticated RCE! Attackers can send crafted HTTP requests to login or API endpoints to execute arbitrary code without any authentication. cc: @zoomeye_team (6k+ targets detected 🎯) #RCE #SmarterMail #CyberSecurity #Infosec

    Post summary

    The post presents a detailed analysis of CVE‑2026‑24423, highlighting a critical unauthenticated remote code execution vulnerability in SmarterMail that allows attackers to execute arbitrary code via crafted HTTP requests.

    00022274
    956 followersView on X
  • SC Media@SCMagazine
    Active Exploitation

    #Ransomware crews are exploiting @SmarterTools' SmarterMail bugs for unauth RCE + admin takeover (CVE-2026-24423, CVE-2026-23760), reported @ReliaQuest. Patch to Build 9511 and isolate mail servers ASAP. #cybersecurity #infosec #CISO #ITsecurity https://bit.ly/3MwftJs

    Post summary

    Ransomware groups are actively exploiting unauthenticated RCE vulnerabilities (CVE-2026-24423, CVE-2026-23760) in SmarterMail; patch Build 9511 and isolate mail servers immediately.

    01020351
    119.3K followersView on X
  • Eric Vanderburg@evanderburg
    Active Exploitation

    #Ransomware attackers are exploiting critical SmarterMail vulnerability (CVE-2026-24423) http://securitytc.com/TQny46 https://t.co/kMoeFb5Vg9

    Post summary

    The post reports that ransomware actors are actively exploiting the SmarterMail vulnerability CVE‑2026‑24423, but does not provide a PoC, exploit code, patch, or detailed technical information.

    02010198
    44.1K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2025-33217 2 - CVE-2023-41064 3 - CVE-2026-24423 4 - CVE-2026-1281 5 - CVE-2024-12084 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The tweet simply lists five trending CVE identifiers without providing any additional context, technical details, or remediation information.

    00021303
    1.7K followersView on X
  • Cloud Virtues@CloudVirtues
    General

    CVE-2026-24423 - SmarterTools SmarterMail vulnerability https://dy.si/f8JzS https://t.co/4a1yCAZA5J

    Post summary

    The tweet references CVE-2026-24423 for SmarterTools SmarterMail but provides no further details or evidence of exploitation, patches, or technical specifics.

    0002071
    10 followersView on X
  • SC Media@SCMagazine
    Active Exploitation

    #Ransomware crews are exploiting @SmarterTools' SmarterMail bugs for unauth RCE + admin takeover (CVE-2026-24423, CVE-2026-23760), reported @ReliaQuest. Patch to Build 9511 and isolate mail servers ASAP. #cybersecurity #infosec #CISO #ITsecurity https://bit.ly/3MwftJs

    Post summary

    Ransomware crews are actively exploiting unauthenticated RCE and admin takeover vulnerabilities in SmarterMail (CVE-2026-24423, CVE-2026-23760), prompting a patch to Build 9511 and isolation of mail servers.

    01001419
    119.3K followersView on X
  • SC Media@SCMagazine
    Active Exploitation

    #Ransomware crews are exploiting @SmarterTools' SmarterMail bugs for unauth RCE + admin takeover (CVE-2026-24423, CVE-2026-23760), reported @ReliaQuest. Patch to Build 9511 and isolate mail servers ASAP. #cybersecurity #infosec #CISO #ITsecurity https://bit.ly/3MwftJs

    Post summary

    Ransomware groups are actively exploiting SmarterMail unauthenticated RCE bugs (CVE‑2026‑24423 and CVE‑2026‑23760), prompting a patch to Build 9511 and urging mail server isolation.

    100101.1K
    119.3K followersView on X
  • 404🌐LABS@404LABSx
    Patch

    🚨 THREAT ALERT: 1,000+ malicious URLs detected. Active Emotet/QakBot campaigns. CVE-2026-24423 SmarterMail RCE exploited by ransomware. Patch now! #CyberSecurity #ThreatIntel

    Post summary

    CVE‑2026‑24423, a Remote Code Execution flaw in SmarterMail, is actively exploited by ransomware; a patch is now available and urgently required.

    0002090
    48 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsmartertoolssmartermail---

Explore more