CVE-2026-25067Disclosure(smartertools / smartermail)

MEDIUMCVSS 5.3 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch smartertools smartermail systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

SmarterTools SmarterMail versions prior to build 9518 contain an unauthenticated path coercion vulnerability in the background-of-the-day preview endpoint. The application base64-decodes attacker-supplied input and uses it as a filesystem path without validation. On Windows systems, this allows UNC paths to be resolved, causing the SmarterMail service to initiate outbound SMB authentication attempts to attacker-controlled hosts. This can be abused for credential coercion, NTLM relay attacks, and unauthorized network authentication.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-706

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • smartermail

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-01-29); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Products
smartermail

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-01-29: 2Mentions · 2026-01-30: 1Active Exploitation · 2026-01-30: 1Patch / Workaround · 2026-01-30: 1Technical Details · 2026-01-29: 2Technical Details · 2026-01-30: 101-2901-30
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-01-292
Disclosure2
2026-01-301
Patch1
Full discourse3 posts
  • ThreatSynop@ThreatSynop
    Patch

    🚨 SmarterMail Patches Critical Unauthenticated RCE (CVE-2026-24423, CVSS 9.3) via ConnectToHub API SmarterMail builds prior to 9511 contain an unauthenticated RCE in the ConnectToHub API method where an attacker can redirect the server to a malicious HTTP host that returns an OS command for execution. SmarterTools also patched an actively exploited critical bug (CVE-2026-23760) and a Windows path-coercion issue enabling NTLM relay/credential coercion (CVE-2026-25067), so upgrading to the latest build is urgent. 🎯 Target: Global/Email Servers #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://thehackernews.com/2026/01/smartermail-fixes-critical.html

    Post summary

    A critical unauthenticated RCE in SmarterMail (CVE‑2026‑24423) has been patched, and the article also notes an actively exploited CVE‑2026‑23760, urging users to upgrade to the latest build.

    0000082
    196 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25067 SmarterMail Unauthenticated Path Coercion Vulnerability in Pre-9518 Versions https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25067

    Post summary

    CVE-2026-25067 describes an unauthenticated path coercion vulnerability in SmarterMail versions before 9518. No exploit, PoC, or mitigation information is disclosed.

    00000122
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25067 SmarterTools SmarterMail versions prior to build 9518 contain an unauthenticated path coercion vulnerability in the background-of-the-day preview endpoint. The appli… https://www.cve.org/CVERecord?id=CVE-2026-25067

    Post summary

    The text announces CVE‑2026‑25067 as an unauthenticated path coercion vulnerability in SmarterMail versions before build 9518, with no PoC, exploit, active exploitation, patch, or false‑positive claim mentioned—technical details of the issue are provided.

    00000353
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsmartertoolssmartermail---

Explore more