
🚨 SmarterMail Patches Critical Unauthenticated RCE (CVE-2026-24423, CVSS 9.3) via ConnectToHub API SmarterMail builds prior to 9511 contain an unauthenticated RCE in the ConnectToHub API method where an attacker can redirect the server to a malicious HTTP host that returns an OS command for execution. SmarterTools also patched an actively exploited critical bug (CVE-2026-23760) and a Windows path-coercion issue enabling NTLM relay/credential coercion (CVE-2026-25067), so upgrading to the latest build is urgent. 🎯 Target: Global/Email Servers #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://thehackernews.com/2026/01/smartermail-fixes-critical.html
Post summary
A critical unauthenticated RCE in SmarterMail (CVE‑2026‑24423) has been patched, and the article also notes an actively exploited CVE‑2026‑23760, urging users to upgrade to the latest build.


