Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»CISA warns of SmarterMail RCE flaw used in ransomware attacks
    Cybersecurity

    CISA warns of SmarterMail RCE flaw used in ransomware attacks

    adminBy adminFebruary 7, 2026No Comments2 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    CISA warns of SmarterMail RCE flaw used in ransomware attacks
    Share
    Facebook Twitter LinkedIn Pinterest Email

    CISA warns of SmarterMail RCE flaw used in ransomware attacks

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that ransomware actors are exploiting CVE-2026-24423, a critical vulnerability in SmarterMail that allows remote code execution without authentication.

    SmarterMail is a self-hosted, Windows-based email server and collaboration platform from SmarterTools. The product provides SMTP/IMAP/POP mail services along with webmail, calendars, contacts, and basic groupware functionality.

    It is commonly deployed by managed service providers (MSPs), small and medium-sized businesses, and hosting companies offering email services. According to SmarterTools, its products are used by roughly 15 million users across 120 countries.

    Wiz

    The CVE-2026-24423 flaw affects SmarterTools SmarterMail versions prior to build 9511, and successful exploitation can lead to remote code execution (RCE) via the ConnectToHub API.

    The vulnerability was discovered and disclosed responsibly  to SmarterTools by security researchers at watchTowr, CODE WHITE, and VulnCheck cybersecurity companies.

    The vendor fixed the flaw on January 15 in SmarterMail Build 9511.

    CISA has now added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog and marked it as actively exploited in ransomware campaigns.

    “SmarterTools SmarterMail contains a missing authentication for a critical function vulnerability in the ConnectToHub API method,” the government agency warns.

    “This could allow the attacker to point the SmarterMail instance to a malicious HTTP server that serves the malicious OS command and could lead to command execution.”

    CISA has given federal agencies and entities with obligations under BOD 22-01 guidance to either apply the security updates and vendor-suggested mitigations or stop using the product by February 26, 2026.

    Around the same time that SmarterTools patched CVE-2026-24423, watchTowr researchers discovered another authentication bypass flaw, internally tracked as WT-2026-0001.

    The flaw, which has no identification number, permits resetting the administrator password without any verification and has been exploited by hackers shortly after the vendor released a patch.

    The researchers base this on anonymous tips, specific calls in the logs of compromised systems, and endpoints that exactly match the vulnerable code path.

    Since then, SmarterMail has fixed additional security flaws rated “critical,” so it is recommended that system administrators update to the most recent build, currently 9526, released on January 30.


    tines

    Modern IT infrastructure moves faster than manual workflows can handle.

    In this new Tines guide, learn how your team can reduce hidden manual delays, improve reliability through automated response, and build and scale intelligent workflows on top of tools you already use.

    attacks CISA Flaw ransomware RCE SmarterMail warns
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleThis Netflix miniseries is by far the best 4-hour binge on the service
    Next Article Super Bowl LX raises network expectations
    admin
    • Website

    Related Posts

    China-Linked APT GopherWhisper Abuses Legitimate Services in Government Attacks

    April 25, 2026

    Researchers Uncover Pre-Stuxnet ‘fast16’ Malware Targeting Engineering Software

    April 25, 2026

    Compromised everyday devices power Chinese cyber espionage operations

    April 25, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    The Facts About Google Click Signals, Rankings, And SEO

    April 25, 2026

    The Xteink S4 Might Be the Pocket E-Reader of My Dreams

    April 25, 2026

    China-Linked APT GopherWhisper Abuses Legitimate Services in Government Attacks

    April 25, 2026

    5 things you never thought a $5 ESP32 could do

    April 25, 2026
    Categories
    • Blogging (68)
    • Cybersecurity (1,506)
    • Privacy & Online Earning (183)
    • SEO & Digital Marketing (925)
    • Tech Tools & Mobile / Apps (1,791)
    • WiFi / Internet & Networking (246)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    The Facts About Google Click Signals, Rankings, And SEO

    April 25, 2026

    The Xteink S4 Might Be the Pocket E-Reader of My Dreams

    April 25, 2026

    China-Linked APT GopherWhisper Abuses Legitimate Services in Government Attacks

    April 25, 2026
    Most Popular
    • The Facts About Google Click Signals, Rankings, And SEO
    • The Xteink S4 Might Be the Pocket E-Reader of My Dreams
    • China-Linked APT GopherWhisper Abuses Legitimate Services in Government Attacks
    • 5 things you never thought a $5 ESP32 could do
    • Why GEO is a reputation problem
    • Your SSD is slowing down, and Windows has been quietly hiding the fix
    • Researchers Uncover Pre-Stuxnet ‘fast16’ Malware Targeting Engineering Software
    • Google Clock 8.8 APK Download by Google LLC
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.