Vulnerability record · CVE-2025-52691 · published 29 December 2025
CVE-2025-52691: SmarterMail unauthenticated arbitrary file upload leading to RCE
Smartertools · Smartermail
SmarterTools SmarterMail contains an unrestricted file upload flaw (CWE-434) that lets an unauthenticated attacker write files to any location on the mail server. Because uploaded files can land anywhere, the flaw can escalate to remote code execution, making it a full compromise of the mail server. It is under active exploitation and listed in CISA KEV.
Description
Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable file upload leading to RCE, CVSS 10.0, active exploitation in CISA KEV with known ransomware use and very high EPSS.
What it is
SmarterTools SmarterMail contains an unrestricted file upload flaw (CWE-434) that lets an unauthenticated attacker write files to any location on the mail server. Because uploaded files can land anywhere, the flaw can escalate to remote code execution, making it a full compromise of the mail server. It is under active exploitation and listed in CISA KEV.
Impact
An unauthenticated attacker can place arbitrary files anywhere on the server and achieve remote code execution, gaining control of the mail server and any data or credentials it holds.
Attack surface
Reachable over the network via the mail server's upload handling with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The record does not specify the exact endpoint or parameter.
Exploitation
CISA KEV lists it as exploited with known ransomware campaign use, and a public proof-of-concept exploit exists (watchTowr reference tagged Exploit). EPSS is 0.857 (99.7th percentile), indicating very high near-term exploitation likelihood.
What to do
- Apply the vendor's patch or mitigation instructions for SmarterMail immediately; if none is available, discontinue use of the product per CISA guidance.
- Restrict network access to the SmarterMail web interface to trusted sources and block untrusted inbound traffic until patched.
- Enforce the CISA KEV remediation due date of 2026-02-16 and follow BOD 22-01 guidance for cloud-hosted instances.
- Audit the mail server for unexpected or recently written files, especially in web-accessible and executable paths.
- Rotate credentials and secrets stored on or accessible from the mail server in case of prior compromise.
Detection
- Monitor for file creation events in web roots, application directories and other unusual paths on the SmarterMail host.
- Alert on upload requests to SmarterMail endpoints from unauthenticated or anomalous sources, and on subsequent execution of newly written files.
- Hunt for webshell-like or executable files with recent timestamps in mail server directories.
- Review server and web logs for upload activity preceding process creation or outbound connections from the mail server.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-52691 to the Known Exploited Vulnerabilities catalog on 26 January 2026 as "SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 16 February 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2025-124/ | Third Party Advisory |
| https://github.com/watchtowrlabs/watchTowr-vs-SmarterMail-CVE-2025-52691?ref=labs.watchtowr.com | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-52691 | US Government Resource |
Track CVE-2025-52691 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-52691), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.