Vendor

SmarterTools

As of , 3 SmarterTools vulnerabilities are on CISA's list of exploited vulnerabilities, 3 of them used in ransomware campaigns; 3 were added in 2026. Patch first: CVE-2025-52691.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2025-52691Unrestricted Upload of File with Dangerous TypeSmarterTools SmarterMailPatch nowRansomware use, listed within a year; Metasploit module0.86
2CVE-2026-24423Missing Authentication for Critical FunctionSmarterTools SmarterMailPatch nowRansomware use, listed within a year0.88
3CVE-2026-23760Authentication Bypass Using an Alternate Path or ChannelSmarterTools SmarterMailPatch nowRansomware use, listed within a year0.97

Added each year

1232026: 332026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20263

Used in ransomware

Changes CISA made to these entries

  1. CVE-2025-52691 SmarterTools SmarterMailRansomware use: Unknown to Known.
  2. CVE-2026-23760 SmarterTools SmarterMailRansomware use: Unknown to Known.
  3. CVE-2026-24423 SmarterTools SmarterMailRansomware use: Unknown to Known.

Every change we recorded