Executive brief
SmarterMail, a popular enterprise email and collaboration server, contains a critical security flaw that allows unauthorized individuals to upload malicious files to the server. An attacker can use this to take full control of the mail server, potentially leading to the theft of sensitive emails, service disruption, or further attacks on the internal network. This vulnerability is currently being exploited in the wild, and organizations should update their installations immediately.
Technical details
An unrestricted file upload vulnerability (CWE-434) exists in SmarterTools SmarterMail versions prior to 100.0.9413. The flaw allows an unauthenticated, remote attacker to upload arbitrary files to any directory on the host file system. By uploading malicious scripts or executables to web-accessible or system directories, an attacker can achieve remote code execution (RCE) with the privileges of the SmarterMail service. This vulnerability has been observed in active exploitation. Users are advised to upgrade to version 100.0.9413 or later to mitigate the risk.
Affected products
- SmarterTools SmarterMail versions up to (excluding) 100.0.9413
Timeline
- 2025-12-28: disclosed: Initial CVE publication and CSA advisory
- 2026-01-02: patched: Version 100.0.9413 identified as the fix version in CPE data
- 2026-01-26: kev added: Added to CISA Known Exploited Vulnerabilities catalog
- 2026-01-26: exploited: Confirmed active exploitation in the wild