Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
internet-facing-service-vulnerabilityproof-of-concept-releaseinternet-exposed-servicerapid-weaponization

SmarterMail Unauthenticated File Upload RCE (CVE-2025-52691) Exposes Thousands of Internet-Facing Servers

Updated 3mo agoFirst seen Jan 14, 20262 sources

A critical SmarterTools SmarterMail vulnerability, CVE-2025-52691, enables remote code execution (RCE) via an unauthenticated arbitrary file upload condition (CWE-434). The issue affects SmarterMail Build 9406 and earlier and is fixed in Build 9413 and later; the NVD lists a CVSS v3.1 score of 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). Successful exploitation can allow full server compromise, including webshell deployment, data theft, and lateral movement under the service’s privileges.

Internet-wide scanning reported 8,001 likely vulnerable IPs out of 18,783 exposed SmarterMail instances (about 42.6% failing checks), with the largest concentration in the United States (~5,000) followed by the UK and Malaysia. Public proof-of-concept exploit code is available, increasing the likelihood of opportunistic exploitation against unpatched, internet-facing deployments; multiple national agencies reportedly issued advisories following disclosure in late December 2025.

Share:
SmarterMail Unauthenticated File Upload RCE (CVE-2025-52691) Exposes Thousands of Internet-Facing Servers
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Jan 13, 20265mo ago

Admins urged to upgrade SmarterMail to patched builds

Security reporting advised administrators to upgrade to SmarterMail Build 9413 or later, preferably Build 9483, and to apply interim mitigations such as restricting admin access and monitoring for suspicious uploads. This guidance was issued in response to the continued exposure of vulnerable internet-facing servers.

Public PoC exploit for CVE-2025-52691 becomes available

Public proof-of-concept exploit code was released for CVE-2025-52691, including examples such as ASPX webshell-based remote code execution. The availability of simple PoCs increased the risk of opportunistic attacks against exposed servers.

SmarterMail RCE flaw CVE-2025-52691 is identified

A critical unauthenticated arbitrary file upload vulnerability, tracked as CVE-2025-52691, was identified in SmarterTools SmarterMail. The flaw affects Build 9406 and earlier and can lead to remote code execution under the service's privileges.

Jan 12, 20265mo ago

Internet scan finds 8,000+ exposed SmarterMail servers still vulnerable

Internet-wide scans conducted on January 12, 2026 found more than 8,000 internet-exposed SmarterMail servers still vulnerable to CVE-2025-52691. Shadowserver UK and Censys data indicated widespread exposure, with the United States hosting the largest number of affected instances.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

6 LINKEDOpen in app
Affected products
1 linked
Smartermail
Organizations
4 linked
SmartertoolsCensysShadowServer FoundationSploitus
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.