SmarterMail Auth Bypass Exploited in the Wild Two Days After Patch Release

Two days after a fix was released, a new security vulnerability in the SmarterTools SmarterMail email program has been actively exploited in the wild.

WatchTowr Labs is tracking the issue as WT-2026-0001, although it does not presently have a CVE identifier. After the exposure management platform’s responsible disclosure on January 8, 2026, SmarterTools patched it with Build 9511 on January 15, 2026.

A specially constructed HTTP request to the “.api/v1/auth/force-reset-password” endpoint has been characterized as an authentication bypass bug that might enable any user to reset the SmarterMail system administrator password.

The worst part, of course, is that the user can directly execute OS [operating system] commands using RCE-as-a-feature functions read more about SmarterMail Auth Bypass Exploited in the Wild Two Days After Patch Release.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *