SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability
SmarterTools · SmarterMail
Date added (CISA)
2026-01-26
Remediation due
2026-02-16
Known ransomware use
Yes
Remediation priority
P1 — known ransomware use · past CISA due date
Description
SmarterTools SmarterMail contains an unrestricted upload of file with dangerous type vulnerability that could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.