Vulnerability
Advisory/Mitigation
Campaign
Exploitation Wave
SmarterMail RCE, password-reset bypass, and ransomware response
Updated 18.02.2026 18:27
Case score 67
Why this score?
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 67
- Main story score
- 61
- Related evidence lift
- +6 / 20
- Contributing updates
- 2
- Context updates
- 1
Top contributors
- Vulnerability Defines the core unauthenticated RCE path in the ConnectToHub API on SmarterMail. main
- Campaign Adds exploit sharing, credential abuse, and ransomware follow-on behavior tied to the SmarterMail flaws. contributes
- Exploitation Wave Adds active exploitation pressure and large exposed-server counts for the same product surface. contributes
- Advisory Mitigation Adds confirmed KEV status, ransomware exploitation warning, and the February 26, 2026 federal remediation deadline for CVE-2026-24423. context
Title history
-
Old: SmarterMail admin-reset abuse and ransomware follow-onNew: SmarterMail RCE, password-reset bypass, and ransomware responseWhy old title changed: The previous title centered on admin-reset abuse and ransomware follow-on, but the accepted scope clearly includes a distinct unauthenticated RCE path and an official response around CVE-2026-24423.The new title better reflects the reader-facing story: parallel SmarterMail exploitation paths, ransomware use, and the active remediation response, while keeping the fixed URL unchanged.
Case score 67
Members 5
Latest activity 18.02.2026 18:27
Active exploitation
KEV: CISA KEV
Patch status varies by member
CVSS: 10.0 Critical
Members 5
First seen 22.01.2026 11:46
Last seen 18.02.2026 18:27
Updated 18.02.2026 18:27
Overview
**SmarterMail** flaws affecting the password-reset path and the **ConnectToHub API** are being exploited against internet-facing mail servers, creating paths to administrator control and, in some activity, command execution. The activity spans mass exposure, rapid exploit and credential sharing, and **Warlock**-linked ransomware follow-on behavior.
**CISA** has put **CVE-2026-24423** on the **Known Exploited Vulnerabilities** catalog with a **February 26, 2026** remediation deadline for federal agencies and other **BOD 22-01** entities, keeping patching and vendor mitigations urgent.
Attackers are targeting internet-facing **SmarterMail** servers through the password-reset path and the **ConnectToHub API**, using **CVE-2026-23760** to bypass authentication and **CVE-2026-24423** to reach unauthenticated remote code execution. The flaws can let intruders reset administrator credentials, seize control of exposed mail systems, and in some activity execute commands on the host. **Build 9511** closed the disclosed **CVE-2026-24423** path and the related reset-path issue tracked in available material.
Broad internet exposure has kept the product under pressure, with defender tracking identifying more than **6,000** likely vulnerable servers. Underground channels quickly circulated proof-of-concept code, offensive tooling, and stolen administrator credentials tied to the SmarterMail flaws, shrinking the response window for exposed organizations. Follow-on activity has included **Warlock**-linked initial access and delayed-encryption ransomware operations that treat compromised mail servers as footholds into internal networks.
**CISA** added **CVE-2026-24423** to the **Known Exploited Vulnerabilities** catalog and set a **February 26, 2026** remediation deadline for federal agencies and other **BOD 22-01** entities. Available material supports active exploitation and ransomware use of the vulnerable surface, but it does not establish the full number of successful compromises or prove that every intrusion followed the same flaw path. Immediate priorities are upgrading **SmarterMail**, applying vendor mitigations, and treating exposed mail servers as high-risk entry points until the vulnerable surface is removed.
Signals
10 derivedImpact signals
Exploitation
CVSS
Exploitation
Active exploitation
CVEs/products
CVE
CVE
Victims/regions
Sector
government
Remediation
Remediation
KEV
CISA KEV
Urgency
High
Status
Campaign status
Active
Threat context
Ransomware
Warlock
Malware context
1 families · 1 toolsTools
Velociraptor
Member happenings
5 related
Vulnerability
SmarterMail unauthenticated RCE in ConnectToHub API (CVE-2026-24423)
Exploitation
No Known Exploitation
Data Type
Email Addresses
Data Type
Physical Addresses
CVSS
10.0 Critical
+1
Vulnerability
SmarterMail unauthenticated RCE in ConnectToHub API (CVE-2026-24423)
Exploitation
No Known Exploitation
Data Type
Email Addresses
Data Type
Physical Addresses
CVSS
10.0 Critical
+1
Exploitation Wave
SmarterMail CVE-2026-23760 mass exploitation wave
Exploitation
Active Exploitation
CVSS
10.0 Critical
Patch
Patch Available
Exploitation Wave
SmarterMail CVE-2026-23760 mass exploitation wave
Exploitation
Active Exploitation
CVSS
10.0 Critical
Patch
Patch Available
Campaign
SmarterMail initial-access ransomware campaign with delayed encryption
Objective
Financial Extortion
Campaign
Active
Campaign
SmarterMail initial-access ransomware campaign with delayed encryption
Objective
Financial Extortion
Campaign
Active
Advisory/Mitigation
CISA SmarterMail remediation guidance for CVE-2026-24423
Exploitation
Active Exploitation
CVSS
9.3 Critical
Urgency
High
Patch
Patch Available
Advisory/Mitigation
CISA SmarterMail remediation guidance for CVE-2026-24423
Exploitation
Active Exploitation
CVSS
9.3 Critical
Urgency
High
Patch
Patch Available
Vulnerability
SmarterMail authentication bypass flaw under active exploitation
Exploitation
Active Exploitation
Exploit
No Known Public Exploit
Data Type
Passwords
Data Type
Email Addresses
+2
Vulnerability
SmarterMail authentication bypass flaw under active exploitation
Exploitation
Active Exploitation
Exploit
No Known Public Exploit
Data Type
Passwords
Data Type
Email Addresses
+2