{"id":207444,"date":"2026-01-27T10:34:00","date_gmt":"2026-01-27T15:34:00","guid":{"rendered":"https:\/\/news-you-need.com\/index.php\/2026\/01\/27\/shadowserver-finds-6000-likely-vulnerable-smartermail-servers-exposed-online\/"},"modified":"2026-01-28T13:45:15","modified_gmt":"2026-01-28T18:45:15","slug":"shadowserver-finds-6000-likely-vulnerable-smartermail-servers-exposed-online","status":"publish","type":"post","link":"https:\/\/news-you-need.com\/index.php\/2026\/01\/27\/shadowserver-finds-6000-likely-vulnerable-smartermail-servers-exposed-online\/","title":{"rendered":"Shadowserver finds 6,000+ likely vulnerable SmarterMail servers exposed online"},"content":{"rendered":"<p><a href=\"https:\/\/securityaffairs.com\/187394\/hacking\/shadowserver-finds-6000-likely-vulnerable-smartermail-servers-exposed-online.html\">Shadowserver finds 6,000+ likely vulnerable SmarterMail servers exposed online<\/a><\/p>\n<p><a href=\"https:\/\/securityaffairs.com\/187394\/hacking\/shadowserver-finds-6000-likely-vulnerable-smartermail-servers-exposed-online.html\">https:\/\/securityaffairs.com\/187394\/hacking\/shadowserver-finds-6000-likely-vulnerable-smartermail-servers-exposed-online.html<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-01-27 10:34:00<\/a><\/p>\n<p>Source Domain: <a href=\"securityaffairs.com\">securityaffairs.com<\/a><\/p>\n<p><h2>Shadowserver finds 6,000+ likely vulnerable SmarterMail servers exposed online<\/h2>\n<\/p>\n<p>\t\t\t\t\t\t\t<span> Pierluigi Paganini<\/span><br \/>\n\t\t\t\t\t\t\t<span><img decoding=\"async\" src=\"https:\/\/securityaffairs.com\/wp-content\/themes\/security_affairs\/images\/clock-icon.svg\" alt=\"\"\/> January 27, 2026<\/span><\/p>\n<p>\t\t\t\t\t\t<img decoding=\"async\" class=\"img-fluid mb-4\" src=\"https:\/\/i0.wp.com\/securityaffairs.com\/wp-content\/uploads\/2026\/01\/image-59.png?fit=1838%2C672&#038;ssl=1\" alt=\"\"\/><\/p>\n<h2 class=\"wp-block-heading\">Shadowserver researchers found 6,000+ SmarterMail servers exposed online and likely vulnerable to a critical auth bypass flaw.<\/h2>\n<p>Nonprofit security organization Shadowserver reported that over 6,000 SmarterMail servers are exposed on the internet and likely vulnerable to attacks exploiting a critical authentication bypass flaw tracked as CVE-2026-23760. Cybersecurity firm watchTowr disclosed the vulnerability on January 8, and SmarterTools addressed it on January 15, without assigning a CVE.<\/p>\n<p>\u201cSmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts.\u201d reads the advisory. \u201cAn unauthenticated attacker can supply a target administrator username and a new password to reset the account, resulting in full administrative compromise of the SmarterMail instance.\u201d<\/p>\n<p> watchTowr researchers released a proof-of-concept exploit that only needs the admin username.<\/p>\n<p>An unauthenticated attacker can exploit the flaw to hijack administrator accounts and achieve remote code execution on the target, potentially leading to a full takeover of vulnerable servers.<\/p>\n<p>Shadowserver reported that over 6,000 SmarterMail servers\u00a0are likely vulnerable, based on their version check. The researchers also observed exploitation attempts in attacks in the wild.<\/p>\n<p lang=\"en\" dir=\"ltr\">We added SmarterTools SmarterMail CVE-2026-23760 RCE to our daily Vulnerable HTTP scans.  Around 6000 IPs globally found likely vulnerable based on our version check.  We also see exploitation attempts in the wild. <\/p>\n<p>CVE-2026-23760 Geo Treemap View:  https:\/\/t.co\/QqZ674VxXG pic.twitter.com\/jDufbmo67s<\/p>\n<p>\u2014 The&#8230;<br \/>\n<br \/><a href=\"https:\/\/securityaffairs.com\/187394\/hacking\/shadowserver-finds-6000-likely-vulnerable-smartermail-servers-exposed-online.html\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Shadowserver finds 6,000+ likely vulnerable SmarterMail servers exposed online https:\/\/securityaffairs.com\/187394\/hacking\/shadowserver-finds-6000-likely-vulnerable-smartermail-servers-exposed-online.html Publish Date: 2026-01-27 10:34:00 Source&#8230;<\/p>\n","protected":false},"author":1,"featured_media":207445,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/securityaffairs.com\/wp-content\/uploads\/2026\/01\/image-59.png","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[24,31,27],"class_list":["post-207444","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity","tag-exploit","tag-vulnerability"],"_links":{"self":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/207444"}],"collection":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=207444"}],"version-history":[{"count":1,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/207444\/revisions"}],"predecessor-version":[{"id":207446,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/207444\/revisions\/207446"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/207445"}],"wp:attachment":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=207444"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=207444"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=207444"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}