ZoomEye[verified]@zoomeye_teamDisclosure
The tweet announces a newly disclosed unauthenticated RCE vulnerability in SmarterMail (CVE‑2026‑24423) with detailed technical information but no PoC, exploit code, active exploitation, or patch updates.
piyokango[verified]@piyokangoActive Exploitation
CISA added CVE-2025-11953 and CVE-2026-24423 to its catalog after confirming active exploitation, especially in ransomware cases, though no patch or exploit tool is disclosed.
ReliaQuest[verified]@ReliaQuestActive Exploitation
ReliaQuest reports active exploitation of SmarterMail CVE‑2026‑23760 by the Storm‑2603 actor, using authentication bypass to reset passwords and maintain persistence; possible attempts against CVE‑2026‑24423 are also noted.
The Cyber Security Hub™[verified]@TheCyberSecHubActive Exploitation
The post states that ransomware actors are actively exploiting the critical CVE‑2026‑24423 in SmarterMail, but it provides no PoC, exploit code, patch details, or technical specifics.
DarkEye[verified]@darkeye_teamDisclosure
The post presents a detailed analysis of CVE‑2026‑24423, highlighting a critical unauthenticated remote code execution vulnerability in SmarterMail that allows attackers to execute arbitrary code via crafted HTTP requests.
CISA Cyber@CISACyberActive Exploitation
The DHS has added CVE-2025-11953 and CVE-2026-24423 to its Known Exploited Vulnerabilities Catalog, indicating these vulnerabilities are being actively exploited, and it recommends applying mitigations.
The Hacker News@TheHackersNewsActive Exploitation
CISA confirms active ransomware exploitation of SmarterMail RCE (CVE-2026-24423) in the wild and urges federal agencies to patch by Feb 26.
The Hacker News@TheHackersNewsPatch
SmarterMail has released a fix for CVE‑2026‑24423, a critical remote‑code‑execution flaw affecting versions before build 9511, and provides details on the vulnerability and its resolution.