SmarterMail Unauthenticated File Upload RCE (CVE-2025-52691) Exposes Thousands of Internet-Facing Servers
A critical SmarterTools SmarterMail vulnerability, CVE-2025-52691, enables remote code execution (RCE) via an unauthenticated arbitrary file upload condition (CWE-434). The issue affects SmarterMail Build 9406 and earlier and is fixed in Build 9413 and later; the NVD lists a CVSS v3.1 score of 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). Successful exploitation can allow full server compromise, including webshell deployment, data theft, and lateral movement under the service’s privileges.
Internet-wide scanning reported 8,001 likely vulnerable IPs out of 18,783 exposed SmarterMail instances (about 42.6% failing checks), with the largest concentration in the United States (~5,000) followed by the UK and Malaysia. Public proof-of-concept exploit code is available, increasing the likelihood of opportunistic exploitation against unpatched, internet-facing deployments; multiple national agencies reportedly issued advisories following disclosure in late December 2025.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
4 events from the most recent confirmed update back to the earliest known activity.
Admins urged to upgrade SmarterMail to patched builds
Security reporting advised administrators to upgrade to SmarterMail Build 9413 or later, preferably Build 9483, and to apply interim mitigations such as restricting admin access and monitoring for suspicious uploads. This guidance was issued in response to the continued exposure of vulnerable internet-facing servers.
Public PoC exploit for CVE-2025-52691 becomes available
Public proof-of-concept exploit code was released for CVE-2025-52691, including examples such as ASPX webshell-based remote code execution. The availability of simple PoCs increased the risk of opportunistic attacks against exposed servers.
SmarterMail RCE flaw CVE-2025-52691 is identified
A critical unauthenticated arbitrary file upload vulnerability, tracked as CVE-2025-52691, was identified in SmarterTools SmarterMail. The flaw affects Build 9406 and earlier and can lead to remote code execution under the service's privileges.
Internet scan finds 8,000+ exposed SmarterMail servers still vulnerable
Internet-wide scans conducted on January 12, 2026 found more than 8,000 internet-exposed SmarterMail servers still vulnerable to CVE-2025-52691. Shadowserver UK and Censys data indicated widespread exposure, with the United States hosting the largest number of affected instances.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
2 references tracked. Mallory keeps watching after this page renders.
See the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


