Find notable cyber news and cases, enriched with sources, timelines, and signals.
Vulnerability Advisory/Mitigation Campaign Exploitation Wave

SmarterMail RCE, password-reset bypass, and ransomware response

Updated 18.02.2026 18:27
Case score 67
Members 5 First seen 22.01.2026 11:46 Latest activity 18.02.2026 18:27

Overview

**SmarterMail** flaws affecting the password-reset path and the **ConnectToHub API** are being exploited against internet-facing mail servers, creating paths to administrator control and, in some activity, command execution. The activity spans mass exposure, rapid exploit and credential sharing, and **Warlock**-linked ransomware follow-on behavior. **CISA** has put **CVE-2026-24423** on the **Known Exploited Vulnerabilities** catalog with a **February 26, 2026** remediation deadline for federal agencies and other **BOD 22-01** entities, keeping patching and vendor mitigations urgent.
Latest development Open development history 5 earlier developments watchTowr flags SmarterMail exploitation in the wild watchTowr said it was tipped off on January 21 that CVE-2026-23760 was being exploited in the wild against SmarterMail instances.
  1. Earlier development

    SmarterTools fixes CVE-2026-24423 in SmarterMail Build 9511

    SmarterTools releases SmarterMail Build 9511 on January 15, 2026, fixing CVE-2026-24423 in versions prior to build 9511 and closing the ConnectToHub API path that could permit unauthenticated remote code execution.

  2. Earlier development

    Build 9511 patches SmarterMail RCE

    SmarterTools released Build 9511 for SmarterMail on January 15, 2026, fixing CVE-2026-24423, an unauthenticated remote code execution flaw in the ConnectToHub API method affecting versions prior to Build 9511.

  3. Earlier development

    watchTowr reports SmarterMail authentication bypass to SmarterTools

    watchTowr reported a SmarterMail authentication bypass in the password reset API to SmarterTools on January 8, starting the remediation cycle for versions prior to build 9511.

  4. Earlier development

    Shadowserver tracks thousands of vulnerable SmarterMail instances

    Shadowserver tracked over 6,000 SmarterMail servers flagged as likely vulnerable to CVE-2026-23760, including more than 4,200 across North America and nearly 1,000 in Asia, while Macnica scans found over 8,550 SmarterMail instances still vulnerable.

  5. Earlier development

    Responsible disclosure of SmarterMail WT-2026-0001

    watchTowr Labs disclosed the SmarterMail authentication bypass tracked as WT-2026-0001 to SmarterTools, identifying the /api/v1/auth/force-reset-password endpoint as the vulnerable path and starting the remediation process for the affected mail software.

Signals

Impact signals
Exploitation
CVEs/products
Geographic context
Remediation
Status
Threat context

Threat actor context

2 listed

Malware & tooling context

1 families · 1 tools
Tools

Technical intelligence

Existing Case data

Member happenings

Vulnerability SmarterMail unauthenticated RCE in ConnectToHub API (CVE-2026-24423)
Updated 30.01.2026 09:09 Lead Contribution 61
Exploitation No Known Exploitation Data Type Email Addresses Data Type Physical Addresses CVSS 10.0 Critical 1 more in details
All signals
Exploitation No Known Exploitation Data Type Email Addresses Data Type Physical Addresses CVSS 10.0 Critical Patch Patch Available

**SmarterMail** versions prior to **Build 9511** contain **CVE-2026-24423**, an **unauthenticated remote code execution** flaw in the **ConnectToHub API** that could let an attacker run arbitrary commands. The bug affects the email software’s exposed API surface and creates a direct compromise risk for unpatched deployments. **Build 9511** fixes the issue, making prompt upgrading the key remediation path.

Exploitation Wave SmarterMail CVE-2026-23760 mass exploitation wave
Updated 27.01.2026 16:09 Scoring Support Contribution 2
Exploitation Active Exploitation CVSS 10.0 Critical Patch Patch Available

**CVE-2026-23760** is being exploited against **SmarterMail** to bypass authentication on **internet-facing mail servers**, creating takeover risk across **thousands of exposed instances**. Defenders have tracked more than **6,000 likely vulnerable servers** and over **8,550** still exposed, while **CISA** added the flaw to its **actively exploited** list and set a **February 16** remediation deadline for U.S. agencies. The vulnerability is an **authentication bypass** in the **password reset API** that can let an attacker reset a system administrator password, and **SmarterTools** released a fix in **Build 9511** with further protection in **Build 9526**.

Campaign SmarterMail initial-access ransomware campaign with delayed encryption
Updated 18.02.2026 18:27 Scoring Support Contribution 2
Objective Financial Extortion Campaign Active

A **SmarterMail** ransomware campaign is using newly disclosed email-server flaws for **initial access** and delaying encryption, raising the risk that exposed mail systems become footholds into internal networks. The operation matters because the same weaknesses are being weaponized quickly across **Internet-facing servers**, shrinking the window for defenders. Underground sharing of **PoC exploits** and stolen credentials is accelerating exploitation, and some activity is being tied to the **Warlock ransomware group**. **CISA** later confirmed active ransomware exploitation by adding **CVE-2026-24423** to the **KEV** catalog.

Advisory/Mitigation CISA SmarterMail remediation guidance for CVE-2026-24423
Updated 06.02.2026 19:16 Context
Exploitation Active Exploitation CVSS 9.3 Critical Urgency High Patch Patch Available

**SmarterMail** is at the center of a **CVE-2026-24423** remediation and exploitation wave: the flaw enables **unauthenticated remote code execution** in versions prior to **Build 9511**, while **CVE-2026-23760** adds authentication-bypass risk on exposed email servers. **CISA** added **CVE-2026-24423** to the **Known Exploited Vulnerabilities** catalog after confirming **active ransomware exploitation**, and directed **federal agencies** and other **BOD 22-01** entities to **apply updates**, use **vendor mitigations**, or **stop using the product** by **February 26, 2026**.

Vulnerability SmarterMail authentication bypass flaw under active exploitation
Updated 22.01.2026 11:46 Context
Exploitation Active Exploitation Exploit No Known Public Exploit Data Type Passwords Data Type Email Addresses 2 more in details
All signals
Exploitation Active Exploitation Exploit No Known Public Exploit Data Type Passwords Data Type Email Addresses CVSS 10.0 Critical Patch Patch Available

**SmarterTools SmarterMail** is under **active exploitation** for an **authentication bypass flaw** that can let an attacker **reset the system administrator password** and potentially reach **SYSTEM-level command execution**. The issue is tracked as **WT-2026-0001** and is tied to the **/api/v1/auth/force-reset-password** endpoint. SmarterTools patched the flaw in **Build 9511** on **January 15, 2026**, but abuse was seen **two days later**. The risk is unauthorized elevated access on affected mail servers.