TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2026-24423

CRITICALCISA KEV
9.8

Beschreibung

SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the SmarterMail to the malicious HTTP server, which serves the malicious OS command. This command will be executed by the vulnerable application.

CVE Details

CVSS v3.1 Bewertung9.8
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht1/23/2026
Zuletzt geandert2/6/2026
Quellekev
Honeypot-Sichtungen0

CISA KEV

HerstellerSmarterTools
ProduktSmarterMail
SchwachstellennameSmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability
KEV Aufnahmedatum2026-02-05
Behebungsfrist2026-02-26
Ransomware-NutzungKnown

Betroffene Produkte

smartertools:smartermail

Schwachen (CWE)

CWE-306

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.