Find notable cyber news and cases, enriched with sources, timelines, and signals.
Vulnerability Advisory/Mitigation Campaign Exploitation Wave

SmarterMail RCE, password-reset bypass, and ransomware response

Updated 18.02.2026 18:27
Case score 67
Case score 67 Members 5 Latest activity 18.02.2026 18:27
Active exploitation KEV: CISA KEV Patch status varies by member CVSS: 10.0 Critical
Members 5 First seen 22.01.2026 11:46 Last seen 18.02.2026 18:27 Updated 18.02.2026 18:27

Overview

**SmarterMail** flaws affecting the password-reset path and the **ConnectToHub API** are being exploited against internet-facing mail servers, creating paths to administrator control and, in some activity, command execution. The activity spans mass exposure, rapid exploit and credential sharing, and **Warlock**-linked ransomware follow-on behavior. **CISA** has put **CVE-2026-24423** on the **Known Exploited Vulnerabilities** catalog with a **February 26, 2026** remediation deadline for federal agencies and other **BOD 22-01** entities, keeping patching and vendor mitigations urgent.

Signals

10 derived
Impact signals
Exploitation
CVSS Exploitation Active exploitation
CVEs/products
CVE CVE
Victims/regions
Sector government
Remediation
Remediation KEV CISA KEV Urgency High
Status
Campaign status Active
Threat context
Ransomware Warlock

Malware context

1 families · 1 tools
Tools
Velociraptor

Member happenings

5 related
Vulnerability SmarterMail unauthenticated RCE in ConnectToHub API (CVE-2026-24423)
Updated 30.01.2026 09:09 Lead Contribution 61
Exploitation No Known Exploitation Data Type Email Addresses Data Type Physical Addresses CVSS 10.0 Critical +1

**SmarterMail** versions prior to **Build 9511** contain **CVE-2026-24423**, an **unauthenticated remote code execution** flaw in the **ConnectToHub API** that could let an attacker run arbitrary commands. The bug affects the email software’s exposed API surface and creates a direct compromise risk for unpatched deployments. **Build 9511** fixes the issue, making prompt upgrading the key remediation path.

Exploitation Wave SmarterMail CVE-2026-23760 mass exploitation wave
Updated 27.01.2026 16:09 Scoring Support Contribution 2
Exploitation Active Exploitation CVSS 10.0 Critical Patch Patch Available

**CVE-2026-23760** is being exploited against **SmarterMail** to bypass authentication on **internet-facing mail servers**, creating takeover risk across **thousands of exposed instances**. Defenders have tracked more than **6,000 likely vulnerable servers** and over **8,550** still exposed, while **CISA** added the flaw to its **actively exploited** list and set a **February 16** remediation deadline for U.S. agencies. The vulnerability is an **authentication bypass** in the **password reset API** that can let an attacker reset a system administrator password, and **SmarterTools** released a fix in **Build 9511** with further protection in **Build 9526**.

Campaign SmarterMail initial-access ransomware campaign with delayed encryption
Updated 18.02.2026 18:27 Scoring Support Contribution 2
Objective Financial Extortion Campaign Active

A **SmarterMail** ransomware campaign is using newly disclosed email-server flaws for **initial access** and delaying encryption, raising the risk that exposed mail systems become footholds into internal networks. The operation matters because the same weaknesses are being weaponized quickly across **Internet-facing servers**, shrinking the window for defenders. Underground sharing of **PoC exploits** and stolen credentials is accelerating exploitation, and some activity is being tied to the **Warlock ransomware group**. **CISA** later confirmed active ransomware exploitation by adding **CVE-2026-24423** to the **KEV** catalog.

Advisory/Mitigation CISA SmarterMail remediation guidance for CVE-2026-24423
Updated 06.02.2026 19:16 Context
Exploitation Active Exploitation CVSS 9.3 Critical Urgency High Patch Patch Available

**SmarterMail** is at the center of a **CVE-2026-24423** remediation and exploitation wave: the flaw enables **unauthenticated remote code execution** in versions prior to **Build 9511**, while **CVE-2026-23760** adds authentication-bypass risk on exposed email servers. **CISA** added **CVE-2026-24423** to the **Known Exploited Vulnerabilities** catalog after confirming **active ransomware exploitation**, and directed **federal agencies** and other **BOD 22-01** entities to **apply updates**, use **vendor mitigations**, or **stop using the product** by **February 26, 2026**.

Vulnerability SmarterMail authentication bypass flaw under active exploitation
Updated 22.01.2026 11:46 Context
Exploitation Active Exploitation Exploit No Known Public Exploit Data Type Passwords Data Type Email Addresses +2

**SmarterTools SmarterMail** is under **active exploitation** for an **authentication bypass flaw** that can let an attacker **reset the system administrator password** and potentially reach **SYSTEM-level command execution**. The issue is tracked as **WT-2026-0001** and is tied to the **/api/v1/auth/force-reset-password** endpoint. SmarterTools patched the flaw in **Build 9511** on **January 15, 2026**, but abuse was seen **two days later**. The risk is unauthorized elevated access on affected mail servers.