LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-24423: SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 5, 2026
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Feb 26, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-24423 to its Known Exploited Vulnerabilities catalog on Feb 5, 2026, with a federal patch deadline of Feb 26, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

SmarterTools SmarterMail contains a missing authentication for critical function vulnerability in the ConnectToHub API method. This could allow the attacker to point the SmarterMail instance to a…

SmarterTools SmarterMail contains a missing authentication vulnerability in the ConnectToHub API method. An attacker can direct the server to retrieve and execute operating system commands from an attacker-controlled HTTP server. The issue is under active exploitation in ransomware campaigns, which makes prompt verification and response a priority for any organization running this email server software.

How it works

The weakness is classified as CWE-306, missing authentication for critical function. In the affected API method an unauthenticated caller can supply an external server address that the SmarterMail instance then contacts without further verification.

Am I affected? How to find it in your systems

SmarterMail is an on-premises or self-hosted email server. Locate all instances by querying your asset inventory, network scans, or configuration management database for the product name and any associated web or SMTP ports.

How to remediate

Apply the vendor-supplied update that addresses the missing authentication check in the ConnectToHub API method. After patching, confirm that the updated code enforces authentication on the affected endpoint and that any previously supplied external hub addresses have been removed or reset.

If you can't patch immediately

Follow the mitigations published in the vendor advisory. Where the product is used as a cloud service, apply the controls required by CISA BOD 22-01. If mitigations cannot be implemented, discontinue use of the affected instance until a fix is applied.

If your data may have been exposed

Because the vulnerability is known to be used in ransomware operations, successful exploitation can lead to data theft or encryption. Organizations can run a free exposure scan of their domains and email addresses against known breach data to determine whether related credentials or messages have already appeared in public datasets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSmarterTools · SmarterMail
WeaknessCWE-306
Added to CISA KEVFeb 5, 2026
Federal patch deadlineFeb 26, 2026
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities