CVE-2026-24423 is a critical unauthenticated remote code execution vulnerability affecting SmarterTools SmarterMail versions prior to build 9511, specifically within the ConnectToHub API method. Rated 9.8 CRITICAL (CVSSv3.1), this flaw allows a remote, unauthenticated attacker to execute arbitrary OS commands by directing the vulnerable application to a malicious HTTP server, leading to complete system compromise. This vulnerability is actively exploited in the wild, including in known ransomware campaigns, and was added to CISA's KEV catalog. Exploit Proof-of-Concepts and stolen credentials were rapidly shared in underground channels post-disclosure, indicating high attacker interest and ease of weaponization.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 100.0.9511CPE match | cpe:2.3:a:smartertools:smartermail:*:*:*:*:*:*:*:* | ||
< 100.0.9511CPE matchmatch criteria | cpe:2.3:a:smartertools:smartermail:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.