Skip to content

CVE-2026-24423

CVE

Threat entity extracted from intelligence sources

Frequency
7
occurrences
First Seen
January 30, 2026
Last Seen
February 10, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

A critical vulnerability in SmarterTools' SmarterMail, identified as CVE-2026-24423, is being actively exploited in ransomware attacks. The flaw allows unauthenticated remote code execution via malicious HTTP requests, affecting users of the email and collaboration server. CISA added this vulnerabil...

SmarterMail has patched a critical unauthenticated remote code execution (RCE) vulnerability, identified as CVE-2026-24423, with a CVSS score of 9.3. This flaw allows attackers to execute operating system commands without authentication, potentially compromising affected systems. Users of SmarterMai...

Public Exploits

Checking GitHub for proof-of-concept code…