SmarterTools has released security updates to address a vulnerability in their SmarterMail software. Users and administrators of affected product versions are advised to update to SmarterMail version Build 9413 immediately.
SmarterTools has released security updates to address a vulnerability (CVE-2025-52691) in their SmarterMail software. The vulnerability has a Common Vulnerability Scoring System (CVSS3.1) score of 10 out of 10.
Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.
The vulnerability affects SmarterMail versions Build 9406 and earlier.
Users and administrators of affected product versions are advised to update to SmarterMail version Build 9413 immediately.
CSA would like to express appreciation to Mr Chua Meng Han from the Centre for Strategic Infocomm Technologies (CSIT) for discovering the vulnerability.
Additionally, CSA would like to thank SmarterTools Inc. for their collaboration on the coordinated disclosure of the vulnerability.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
