Junglewise Threat Intelligence

CVE-2026-24423: SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API

CVE-2026-24423 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2026-01-23

Technologies: SmarterTools SmarterMail. Vendors: SmarterTools.

Executive brief

SmarterMail is a popular enterprise-grade email and collaboration server. A critical security flaw allows unauthenticated attackers to remotely execute commands on the server by redirecting the application to a malicious external source. This could lead to a total compromise of the email server, including the theft of sensitive communications, loss of service, and a foothold for further attacks on the corporate network.

Technical details

A missing authentication vulnerability (CWE-306) exists in the ConnectToHub API method within SmarterTools SmarterMail. An unauthenticated remote attacker can exploit this by sending a crafted request that points the SmarterMail instance to a malicious HTTP server. The application then fetches and executes OS commands provided by the attacker's server. This vulnerability is being exploited in the wild and has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The issue is resolved in SmarterMail build 9511.

Affected products

  • SmarterTools SmarterMail Prior to build 9511

Timeline

  • 2026-01-23: disclosed: Initial publication by VulnCheck
  • 2026-02-05: kev added: Added to CISA Known Exploited Vulnerabilities catalog
  • 2026-02-05: advisory: NVD advisory published/updated

Related threats