{"id":208248,"date":"2026-01-30T07:00:00","date_gmt":"2026-01-30T12:00:00","guid":{"rendered":"https:\/\/news-you-need.com\/index.php\/2026\/01\/30\/smartertools-patches-critical-smartermail-flaw-allowing-code-execution\/"},"modified":"2026-01-30T14:20:14","modified_gmt":"2026-01-30T19:20:14","slug":"smartertools-patches-critical-smartermail-flaw-allowing-code-execution","status":"publish","type":"post","link":"https:\/\/news-you-need.com\/index.php\/2026\/01\/30\/smartertools-patches-critical-smartermail-flaw-allowing-code-execution\/","title":{"rendered":"SmarterTools patches critical SmarterMail flaw allowing code execution"},"content":{"rendered":"<p><a href=\"https:\/\/securityaffairs.com\/187496\/security\/smartertools-patches-critical-smartermail-flaw-allowing-code-execution.html\">SmarterTools patches critical SmarterMail flaw allowing code execution<\/a><\/p>\n<p><a href=\"https:\/\/securityaffairs.com\/187496\/security\/smartertools-patches-critical-smartermail-flaw-allowing-code-execution.html\">https:\/\/securityaffairs.com\/187496\/security\/smartertools-patches-critical-smartermail-flaw-allowing-code-execution.html<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-01-30 07:00:00<\/a><\/p>\n<p>Source Domain: <a href=\"securityaffairs.com\">securityaffairs.com<\/a><\/p>\n<p><h2>SmarterTools patches critical SmarterMail flaw allowing code execution<\/h2>\n<\/p>\n<p>\t\t\t\t\t\t\t<span> Pierluigi Paganini<\/span><br \/>\n\t\t\t\t\t\t\t<span><img decoding=\"async\" src=\"https:\/\/securityaffairs.com\/wp-content\/themes\/security_affairs\/images\/clock-icon.svg\" alt=\"\"\/> January 30, 2026<\/span><\/p>\n<p>\t\t\t\t\t\t<img decoding=\"async\" class=\"img-fluid mb-4\" src=\"https:\/\/i0.wp.com\/securityaffairs.com\/wp-content\/uploads\/2026\/01\/Smarter-SmarterMail.png?fit=1200%2C627&#038;ssl=1\" alt=\"\"\/><\/p>\n<h2 class=\"wp-block-heading\">SmarterTools fixed two SmarterMail flaws, including a critical bug (CVE-2026-24423) that could allow arbitrary code execution.<\/h2>\n<p>SmarterTools fixed two security bugs in its SmarterMail email software, including a critical vulnerability, tracked as CVE-2026-24423 (CVSS score of 9.3) that could let attackers run malicious code on affected systems.<\/p>\n<p>\u201cSmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method.\u201d reads the advisory. \u201cThe attacker could point the SmarterMail to the malicious HTTP server, which serves the malicious OS command. This command will be executed by the vulnerable application.\u201d <\/p>\n<p>The researchers Sina Kheirkhah &#038; Piotr Bazydlo of watchTowr, Markus Wulftange of CODE WHITE GmbH, and Cale Black of VulnCheck reported the vulnerability.<\/p>\n<p>SmarterTools addressed the issue in version Build 9511. <\/p>\n<p>SmarterTools also addressed the critical vulnerability CVE-2026-23760 (CVSS score: 9.3), which is actively exploited in the wild. An unauthenticated attacker can exploit the flaw to hijack administrator accounts and achieve remote code execution on the target, potentially leading to a full takeover of vulnerable servers.<\/p>\n<p>This week, nonprofit security organization Shadowserver reported that over 6,000 SmarterMail servers are exposed on the internet and likely vulnerable to attacks exploiting\u00a0CVE-2026-23760. Cybersecurity firm watchTowr disclosed the vulnerability on January 8, and SmarterTools\u00a0addressed\u00a0it on January 15, without assigning a CVE.<\/p>\n<p>\u201cSmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or&#8230;<\/p>\n<p><a href=\"https:\/\/securityaffairs.com\/187496\/security\/smartertools-patches-critical-smartermail-flaw-allowing-code-execution.html\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>SmarterTools patches critical SmarterMail flaw allowing code execution https:\/\/securityaffairs.com\/187496\/security\/smartertools-patches-critical-smartermail-flaw-allowing-code-execution.html Publish Date: 2026-01-30 07:00:00 Source Domain:&#8230;<\/p>\n","protected":false},"author":1,"featured_media":208249,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/securityaffairs.com\/wp-content\/uploads\/2026\/01\/Smarter-SmarterMail.png","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[24,31,27],"class_list":["post-208248","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity","tag-exploit","tag-vulnerability"],"_links":{"self":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/208248"}],"collection":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=208248"}],"version-history":[{"count":1,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/208248\/revisions"}],"predecessor-version":[{"id":208250,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/208248\/revisions\/208250"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/208249"}],"wp:attachment":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=208248"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=208248"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=208248"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}