SmarterMail Auth Bypass Exploited in the Wild Two Days After Patch Release
Two days after a fix was released, a new security vulnerability in the SmarterTools SmarterMail email program has been actively exploited in the wild.
WatchTowr Labs is tracking the issue as WT-2026-0001, although it does not presently have a CVE identifier. After the exposure management platform's responsible disclosure on January 8, 2026, SmarterTools patched it with Build 9511 on January 15, 2026.
A specially constructed HTTP request to the ".api/v1/auth/force-reset-password" endpoint has been characterized as an authentication bypass bug that might enable any user to reset the SmarterMail system administrator password.
The worst part, of course, is that the user can directly execute OS [operating system] commands using RCE-as-a-feature functions read more about SmarterMail Au...

