SmarterMail Fixes Critical Unauthenticated RCE Flaw with CVSS 9.3 Score
Two further security issues in the SmarterMail email program have been fixed by SmarterTools, one of which is serious and might lead to arbitrary code execution.
The vulnerability has a CVSS score of 9.3 out of 10.0 and is tagged as CVE-2026-24423.
SmarterTools SmarterMail versions previous to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method," according to a description of the bug in CVE.org.
The malicious OS [operating system] command is served by the rogue HTTP server, which the attacker may direct SmarterMail to. The vulnerable application will carry out this command.
The vulnerability was found and reported by watchTowr researchers read more about SmarterMail Fixes Critical Unauthenticated RCE Flaw with CVSS 9.3 Score...

