www.crowdsec.net Mass Exploitation of Gravity SMTP Plugin Vulnerability CVE-2026-4020
Article Content
- •CVE-2026-4020 allows unauthorized access to sensitive data in Gravity SMTP plugin.
- •Exploitation began on May 27, 2026, with 412 distinct IPs observed targeting the vulnerability.
- •87% of the attack traffic comes from a coordinated Google Cloud operation using rotating user-agents.
CVE-2026-4020 is an information disclosure vulnerability in the Gravity SMTP WordPress plugin, published on March 31, 2026. The flaw allows unauthenticated visitors to access sensitive system reports, including SMTP credentials and API keys, via a REST API endpoint. Active exploitation began on May 27, 2026, with CrowdSec logging 412 distinct IPs targeting the vulnerability. A significant portion of the traffic, approximately 87%, originates from a Google Cloud fleet, indicating a coordinated operation rather than random probing. Attackers are using a rotating set of user-agents to disguise their activities, complicating detection efforts. As of June 1, 2026, exploitation has shifted into Background Noise, suggesting it has become a routine target for attackers. The vulnerability poses a serious risk to WordPress sites utilizing the Gravity SMTP plugin, as it exposes critical configuration data.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (15)
Following this threat?
Track Bissa and CVE-2026-4020 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…