<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — SmarterTools</title><description>Actively exploited vulnerabilities affecting SmarterTools products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/smartertools.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-24423 — SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-24423</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-24423</guid><description>SmarterMail&apos;s ConnectToHub API method lacks authentication, meaning an unauthenticated attacker can redirect the mail server to a malicious HTTP server of their choosing and execute arbitrary OS commands on the underlying system. This is a critical server-side vulnerability with no user interaction required. It has already been linked to active ransomware campaigns, making exposed SmarterMail instances at immediate risk of full system compromise and data encryption.</description><pubDate>Thu, 05 Feb 2026 00:00:00 GMT</pubDate><category>SmarterTools</category><category>SmarterMail</category></item><item><title>CVE-2025-52691 — SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-52691</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-52691</guid><description>SmarterMail contains a critical flaw allowing unauthenticated attackers to upload arbitrary files anywhere on the mail server. Because no authentication is required and files can land in any location, attackers can place executable content that runs with server privileges — achieving full remote code execution. This vulnerability is already being actively exploited in ransomware campaigns, making exposed mail servers an immediate, high-priority target with potential for complete system compromise.</description><pubDate>Mon, 26 Jan 2026 00:00:00 GMT</pubDate><category>SmarterTools</category><category>SmarterMail</category></item><item><title>CVE-2026-23760 — SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-23760</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-23760</guid><description>SmarterMail&apos;s password reset API has a critical flaw: the endpoint that forces a password reset on administrator accounts accepts anonymous requests and doesn&apos;t verify the existing password or a valid reset token. An attacker who knows only an admin username can remotely set a new password and take full control of the mail server. This vulnerability is already being exploited in ransomware attacks, making it an urgent threat to any organization running SmarterMail.</description><pubDate>Mon, 26 Jan 2026 00:00:00 GMT</pubDate><category>SmarterTools</category><category>SmarterMail</category></item></channel></rss>