Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
internet-facing-service-vulnerabilityproof-of-concept-releasewidely-deployed-product-advisoryinitial-access-method

SmarterMail Flaws Expose Email Servers to Authentication Bypass and RCE

Updated 1mo agoFirst seen May 25, 20264 sources

Multiple severe vulnerabilities in SmarterMail exposed internet-facing mail servers to compromise, including CVE-2025-52691, an unauthenticated arbitrary file upload flaw that can lead to immediate remote code execution, and CVE-2026-23760, an authentication bypass tied to the password reset API. Public reporting said CVE-2025-52691 affected Build 9406 and earlier, carried a CVSS 10.0 rating, and allowed attackers with network access to place files in arbitrary server locations and execute code with the privileges of the SmarterMail service.

Advisories from Censys highlighted both issues, while a public GitHub proof-of-concept for CVE-2026-23760 increased the risk of opportunistic exploitation. SmarterTools reportedly fixed the file upload vulnerability in Build 9413, with later builds available afterward, and security reporting warned that successful compromise of a mail gateway could expose customer email, credentials, and connected backend systems. The flaws were described as especially dangerous for hosting providers and organizations running exposed SmarterMail instances because they enable unauthenticated access paths that can quickly escalate to full server compromise.

Share:
SmarterMail Flaws Expose Email Servers to Authentication Bypass and RCE
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Jan 27, 20265mo ago

Advisory issued for SmarterMail authentication bypass CVE-2026-23760

A January 27 advisory documented CVE-2026-23760 as a SmarterMail authentication bypass issue. The advisory was later referenced by Censys.

Jan 24, 20265mo ago

PoC repository published for SmarterMail CVE-2026-23760

A GitHub repository was published for CVE-2026-23760, describing an authentication bypass in SmarterMail via the password reset API. This made public exploit-related material available for the vulnerability.

Dec 30, 20256mo ago

CVE-2025-52691 advisory highlights critical SmarterMail RCE risk

An advisory dated December 30 described CVE-2025-52691 as a critical unauthenticated arbitrary file upload vulnerability in SmarterMail, noting it was trivial to exploit and had not been publicly reported as actively exploited at that time. The issue was credited to Chua Meng Han of Singapore's CSIT and was also highlighted in a Cyber Security Agency of Singapore alert.

Oct 9, 20259mo ago

SmarterTools releases SmarterMail Build 9413 to fix CVE-2025-52691

SmarterTools fixed the unauthenticated arbitrary file upload vulnerability CVE-2025-52691 in SmarterMail Build 9413. The flaw affected Build 9406 and earlier and could allow remote code execution.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.