cvedb.io
CVE-2026-24423
CRITICAL · CVSS 9.8 ⚠ KEV — EXPLOITED
EPSS exploitation probability: 100%
⚠ Listed in the CISA Known Exploited Vulnerabilities catalog — actively exploited.
Published 2026-02-05 · Last modified 2026-08-04T05:16:38.320

Summary

SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the SmarterMail to the malicious HTTP server, which serves the malicious OS command. This command will be executed by the vulnerable application.

Affected products

SmarterTools — SmarterMail

Does this affect you?

Add your gear to cvedb and we'll alert you only when SmarterTools ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.