← Vulnerability feed

Vulnerability record · CVE-2026-24423 · published 23 January 2026

CVE-2026-24423: SmarterMail ConnectToHub API unauthenticated remote code execution

Smartertools · Smartermail

SmarterTools SmarterMail builds prior to 9511 expose the ConnectToHub API method without authentication, allowing an attacker to redirect the application to an attacker-controlled HTTP server that returns an OS command. The application then executes that command, giving remote code execution on the mail server. Because it is unauthenticated and network-reachable, it is a severe pre-auth compromise path for internet-facing SmarterMail instances.

9.3 CVSS 4.0 Critical CISA KEV since 5 Feb 2026 Known ransomware use EPSS 88% · top 0.2% CWE-306 · Missing authentication for critical function
9.3CVSS 4.0 base score
88%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
4References
4 Aug 2026Last modified by NVD

Description

SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the SmarterMail to the malicious HTTP server, which serves the malicious OS command. This command will be executed by the vulnerable application.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated network RCE with a CVSS 4.0 score of 9.3, KEV listing with known ransomware use, and very high EPSS make this an urgent patch-first issue.

What it is

SmarterTools SmarterMail builds prior to 9511 expose the ConnectToHub API method without authentication, allowing an attacker to redirect the application to an attacker-controlled HTTP server that returns an OS command. The application then executes that command, giving remote code execution on the mail server. Because it is unauthenticated and network-reachable, it is a severe pre-auth compromise path for internet-facing SmarterMail instances.

Impact

An unauthenticated attacker can execute arbitrary OS commands on the SmarterMail host, leading to full server compromise, data theft, and use of the host as a foothold for further intrusion.

Attack surface

Reachable over the network via the ConnectToHub API method; the CVSS 4.0 vector shows PR:N and UI:N, so no authentication or user interaction is required. The attacker only needs to control an HTTP server that SmarterMail will contact.

Exploitation

CISA added this to KEV on 2026-02-05 with known ransomware campaign use, and EPSS is 0.87988 (99.756th percentile), indicating active exploitation is expected or observed. No public exploit code details are provided in the record.

What to do

  • Upgrade SmarterMail to build 9511 or later immediately.
  • If patching is not possible, restrict network access to the SmarterMail web/API interface to trusted sources and block outbound HTTP from the server.
  • Follow CISA KEV required action and BOD 22-01 guidance for cloud services, or discontinue use if mitigations are unavailable.
  • Isolate or rebuild any SmarterMail host that may have been exposed, and rotate credentials and secrets stored on it.
  • Monitor vendor release notes for further guidance and confirm the installed build number after patching.

Detection

  • Search SmarterMail logs for requests to the ConnectToHub API method, especially from unexpected or external source IPs.
  • Monitor outbound HTTP connections from the SmarterMail server to unfamiliar or newly registered hosts.
  • Alert on unexpected child processes spawned by the SmarterMail service (for example cmd.exe, powershell.exe, or shell).
  • Review host and network telemetry for post-exploitation activity such as new services, scheduled tasks, or credential access on SmarterMail servers.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-24423 to the Known Exploited Vulnerabilities catalog on 5 February 2026 as "SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 26 February 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-24423 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-52691SmarterMail unauthenticated arbitrary file upload leading to RCESmarterTools SmarterMail contains an unrestricted file upload flaw (CWE-434) that lets an unauthenticated attacker write files to any location on the…KEVEPSS 86%analysed9.3CVE-2026-23760SmarterMail password reset API authentication bypassSmarterMail builds prior to 9511 expose a force-reset-password endpoint that accepts anonymous requests and does not verify the current password or a…KEVEPSS 97%analysed9.8CVE-2021-32234Smartertools smartermail vulnerabilitySmarterTools SmarterMail 16.x through 100.x before 100.0.7803 allows remote code execution.EPSS 2.2%9.8CVE-2019-7214SmarterMail deserialization of untrusted data enables unauthenticated RCESmarterTools SmarterMail 16.x before build 6985 deserializes untrusted data, letting an unauthenticated attacker execute commands on the server when …EPSS 85%analysed8.7CVE-2026-7807Smartertools smartermail path traversal vulnerabilitySmarterTools SmarterMail builds prior to 9560 contain a local file inclusion vulnerability in the /api/v1/report/summary/{type} API endpoint that all…EPSS 0.34%8.2CVE-2026-40514Smartertools smartermail vulnerabilitySmarterTools SmarterMail builds prior to 9610 contain a cryptographic weakness in the file and email sharing endpoints that use DES-CBC encryption wi…EPSS 0.26%8.2CVE-2019-7212Smartertools smartermail hard-coded credentials vulnerabilitySmarterTools SmarterMail 16.x before build 6985 has hardcoded secret keys. An unauthenticated attacker could access other users’ emails and file atta…EPSS 1.0%8.1CVE-2020-29548Smartertools smartermail command injection vulnerabilityAn issue was discovered in SmarterTools SmarterMail through 100.0.7537. Meddler-in-the-middle attackers can pipeline commands after a POP3 STLS comma…EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2026-24423), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.