6000+ Vulnerable SmarterTools SmarterMail Servers Exposed to Actively Exploited RCE Vulnerability
Over 6,000 SmarterMail servers currently exposed online are running vulnerable versions susceptible to remote code execution (RCE) attacks.
Over 6,000 SmarterMail servers currently exposed online are running vulnerable versions susceptible to remote code execution (RCE) attacks.
Security researchers have detected these flaws through routine HTTP vulnerability scans, with active exploitation attempts already observed.
This situation presents a significant risk to organizations worldwide that depend on SmarterMail for enterprise email operations.
The vulnerability, identified as CVE-2026-23760 , is a critical authentication bypass issue in the SmarterMail password reset API, affecting all versions prior to Build 9511, released on Thu, Jan 15, 2026.
With a CVSS score of 9.3, this vulnerability poses an extreme risk to affected systems.
The flaw resides in the /api/v1/auth/force-reset-password endpoint, allowing unauthenticated requests without password verification or reset tokens when targeting administrator accounts.
Over 6,000 SmarterMail servers currently exposed online are running vulnerable versions susceptible to remote code execution (RCE) attacks.
An attacker can exploit this vulnerability by supplying any administrator username with a new password, leading to an immediate administrative account takeover.
Furthermore, SmarterMail administrators have built-in functionality that allows direct execution of operating system commands through the Settings interface, escalating the compromise to SYSTEM-level access on the host machine.
Multiple security organizations have confirmed active exploitation since at least Sat, Jan 17, 2026, just two days post-patch release.
Threat actors have used compromised administrator accounts to create malicious System Events configured to execute reconnaissance commands on vulnerable hosts. This attack chain reveals a sophisticated understanding of SmarterMail architecture, as attackers systematically reset accounts, obtain authentication tokens, and install persistent backdoors.
Reports confirm exploitation of the vulnerability in production environments.
Geographically distributed scanning by Shadowserver indicates vulnerable instances across multiple continents, although specific regional details have not been publicly disclosed.
The identification of 6,000 vulnerable IPs highlights a substantial attack surface, particularly as many organizations remain unaware of available patches.
SmarterTools strongly recommends updating to the latest build immediately. Organizations should prioritize patching as attackers continue to target unpatched instances. Security teams are advised to review administrator account activity logs for unauthorized password resets, investigate potential web shells or malware installed via exploitation, and ensure system backups remain uncompromised.
Based on reporting by Cyber Security News.
