CVE-2026-40514Disclosure(smartertools / smartermail)

LOWCVSS 9.1 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

SmarterTools SmarterMail builds prior to 9610 contain a cryptographic weakness in the file and email sharing endpoints that use DES-CBC encryption with keys and initialization vectors derived from System.Random seeded with insufficient entropy, reducing the seed space to approximately 19,000 possible values. An unauthenticated attacker can use the attachment download endpoint as an oracle to determine the seed in use and derive encryption keys and initialization vectors to forge sharing tokens for arbitrary emails, attachments, or file storage contents without prior access to the targeted content.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-338

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • smartermail

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Products
smartermail

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-27: 204-27
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets3 URLs
Full discourse2 posts
  • CVE@CVEnew
    General

    CVE-2026-40514 SmarterTools SmarterMail builds prior to 9610 contain a cryptographic weakness in the file and email sharing endpoints that use DES-CBC encryption with keys and initi… https://www.cve.org/CVERecord?id=CVE-2026-40514

    Post summary

    The snippet references CVE-2026-40514, noting a cryptographic weakness in SmarterTools SmarterMail, but offers no further detail on PoC, exploitation, patches, or technical specifics.

    0000082
    57.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40514 Cryptographic Weakness in SmarterTools SmarterMail Prior to 9610 ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40514 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The tweet announces the existence of the CVE-2026-40514 vulnerability in SmarterTools SmarterMail and provides a link to a vulnerability details page, but offers no further technical, exploit, or mitigation information.

    0000032
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsmartertoolssmartermail---

Explore more