tag
Smartermail
Critical
SmarterMail Auth Bypass via Password Reset to Pre-Auth RCE (CVE-2025-52691 / WT-2026-0001)
CVE-2025-52691·
SmarterMail (SmarterTools webmail/mail server)
patched
Critical
SmarterMail Unauthenticated Admin Password Reset (CVE-2026-0001 / WT-2026-0001)
CVE-2026-0001 (tracked publicly as WT-2026-0001)·
SmarterTools SmarterMail (webmail/admin control panel), typically on port 9998
patched
Critical
SmarterMail ConnectToHub Unauthenticated SSRF Leading to Remote Command Execution — CVE-2026-24423
CVE-2026-24423·
SmarterMail (ConnectToHub / node clustering feature)
unpatched
Critical
SmarterMail Admin Password-Reset Authentication Bypass (CVE-2026-23760)
CVE-2026-23760·
SmarterTools SmarterMail
patched