The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that ransomware actors are exploiting CVE-2026-24423, a critical vulnerability in SmarterMail that allows remote code execution without authentication. SmarterMail is a self-hosted, Windows-based email server and collaboration platform from SmarterTools. The product provides SMTP/IMAP/POP mail services along with webmail, calendars, contacts, and basic groupware functionality. It is commonly deployed by managed service providers (MSPs), small and medium-sized businesses, and hosting companies offering email services. According to SmarterTools, its products are used by roughly 15 million users across 120 countries. The CVE-2026-24423 flaw affects SmarterTools SmarterMail versions prior to build 9511, and successful exploitation can lead to remote code execution (RCE) via the ConnectToHub API. The vulnerability was discovered and disclosed responsibly to SmarterTools by security researchers at watchTowr, CODE WHITE, and VulnCheck cybersecurity companies. The vendor fixed the flaw on January 15 in SmarterMail Build 9511. CISA has now added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog and marked it as actively exploited in ransomware campaigns. “SmarterTools SmarterMail contains a missing authentication for a critical function vulnerability in the ConnectToHub API method,” the government agency warns. “This could allow the attacker to point the SmarterMail instance to a malicio...
CISA warns of SmarterMail RCE flaw used in ransomware attacks
BleepingComputer
·Bill Toulas
·Published Feb 6, 2026
·Updated
Affected Software
1 affected component
SmarterTools SmarterMail<9511
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the warning from CISA about a critical remote code execution vulnerability in SmarterMail being exploited in ransomware attacks.
2
What vulnerability is being exploited in ransomware attacks according to CISA?
The vulnerability identified is CVE-2026-24423, which allows for remote code execution without authentication.
3
Which software does the vulnerability affect?
The vulnerability affects SmarterTools SmarterMail versions up to exclusive version 9511.
4
What are the potential security implications of the SmarterMail RCE flaw?
The exploitation of this RCE flaw can lead to unauthorized remote access and control over affected SmarterMail servers.
5
What should users of SmarterMail do in response to this warning?
Users of SmarterMail should apply the latest security updates and patches to mitigate the risk of exploitation.