SmarterMail RCE, password-reset bypass, and ransomware response
Case score 67
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 67
- Main story score
- 61
- Related evidence lift
- +6 / 20
- Contributing updates
- 2
- Context updates
- 1
- Vulnerability Defines the core unauthenticated RCE path in the ConnectToHub API on SmarterMail. main
- Campaign Adds exploit sharing, credential abuse, and ransomware follow-on behavior tied to the SmarterMail flaws. contributes
- Exploitation Wave Adds active exploitation pressure and large exposed-server counts for the same product surface. contributes
- Advisory Mitigation Adds confirmed KEV status, ransomware exploitation warning, and the February 26, 2026 federal remediation deadline for CVE-2026-24423. context
-
Old: SmarterMail admin-reset abuse and ransomware follow-onNew: SmarterMail RCE, password-reset bypass, and ransomware responseWhy old title changed: The previous title centered on admin-reset abuse and ransomware follow-on, but the accepted scope clearly includes a distinct unauthenticated RCE path and an official response around CVE-2026-24423.The new title better reflects the reader-facing story: parallel SmarterMail exploitation paths, ransomware use, and the active remediation response, while keeping the fixed URL unchanged.
Overview
Latest development Open development history watchTowr flags SmarterMail exploitation in the wild watchTowr said it was tipped off on January 21 that CVE-2026-23760 was being exploited in the wild against SmarterMail instances.
-
SmarterTools fixes CVE-2026-24423 in SmarterMail Build 9511
SmarterTools releases SmarterMail Build 9511 on January 15, 2026, fixing CVE-2026-24423 in versions prior to build 9511 and closing the ConnectToHub API path that could permit unauthenticated remote code execution.
-
Build 9511 patches SmarterMail RCE
SmarterTools released Build 9511 for SmarterMail on January 15, 2026, fixing CVE-2026-24423, an unauthenticated remote code execution flaw in the ConnectToHub API method affecting versions prior to Build 9511.
-
watchTowr reports SmarterMail authentication bypass to SmarterTools
watchTowr reported a SmarterMail authentication bypass in the password reset API to SmarterTools on January 8, starting the remediation cycle for versions prior to build 9511.
-
Shadowserver tracks thousands of vulnerable SmarterMail instances
Shadowserver tracked over 6,000 SmarterMail servers flagged as likely vulnerable to CVE-2026-23760, including more than 4,200 across North America and nearly 1,000 in Asia, while Macnica scans found over 8,550 SmarterMail instances still vulnerable.
-
Responsible disclosure of SmarterMail WT-2026-0001
watchTowr Labs disclosed the SmarterMail authentication bypass tracked as WT-2026-0001 to SmarterTools, identifying the /api/v1/auth/force-reset-password endpoint as the vulnerable path and starting the remediation process for the affected mail software.