Vendor
SmarterTools
As of , 3 SmarterTools vulnerabilities are on CISA's list of exploited vulnerabilities, 3 of them used in ransomware campaigns; 3 were added in 2026. Patch first: CVE-2025-52691.
Patch first
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 1 | CVE-2025-52691Unrestricted Upload of File with Dangerous Type | SmarterTools SmarterMail | Patch nowRansomware use, listed within a year; Metasploit module | 0.86 | ||
| 2 | CVE-2026-24423Missing Authentication for Critical Function | SmarterTools SmarterMail | Patch nowRansomware use, listed within a year | 0.88 | ||
| 3 | CVE-2026-23760Authentication Bypass Using an Alternate Path or Channel | SmarterTools SmarterMail | Patch nowRansomware use, listed within a year | 0.97 |
Added each year
Show the numbers
| Period | entries added |
|---|---|
| 2026 | 3 |