CVE-2026-24423
SmarterMail before build 9511 has a flaw that lets anyone on the internet run arbitrary commands on the server. An attacker can trick the mail server into connecting to a malicious site that sends a command, which the server will execute. This can let the attacker take full control of the machine.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
SmarterTools SmarterMail versions prior to build 9511, used by organizations that host email services.
Real-world impact
An attacker could run any command on the mail server, potentially taking full control, stealing data, or using the server for further attacks.
Why this severity
The CVSS score of 9.3 reflects that the flaw is easy to exploit from the internet, requires no authentication, and allows an attacker to run arbitrary code with full system privileges, which is why it is rated critical.
What to do about it
- 01Upgrade SmarterMail to build 9511 or later.
NVD description
Timeline
- Jan 23, 2026 · Jan 23, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Feb 5, 2026 · Feb 5, 2026Confirmed exploited (CISA KEV)CISA added it to the Known Exploited Vulnerabilities catalog — attackers are using it in the wild.
- Feb 26, 2026 · Feb 26, 2026CISA remediation deadlineFederal agencies are required to remediate by this date.
- Aug 4, 2026 · 1d agoAdvisory updatedThe NVD record was last revised.
- Aug 4, 2026 · 1d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- code-white.com/public-vulnerability-list/third party advisory
- smartertools.com/smartermail/release-notes/c…release notes
- vulncheck.com/advisories/smartertools-sma…third party advisory
- cisa.gov/known-exploited-vulnerabili…us government resource