CVE-2025-52691Critical· 10.0▾ Hadal⚠ Exploited in the wildPoC availableSuccessful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.
▾ Hadal zone — Critical and actively exploited (CISA KEV / 0day)
impact 55 · likelihood 17.1 · exploitation 25 · ransomware 5
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 3 sources. Availability, not in-the-wild use.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Feb 16, 2026
Last analysed / modified upstream
86%
9 GitHub repos · Metasploit ×1 · Nuclei ×1 (last check)
Added to the CISA catalog on Jan 26, 2026. Federal remediation due Feb 16, 2026. View catalog ↗
Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.
smartermail < 100.0.9413Upgrade past the affected range:
smartermail 100.0.9413Connected by shared product, vendor, weakness, or advisory.
CVE-2024-50623Critical· 9.8In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.
CVE-2026-24423Critical· 9.8SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method
CVE-2026-23760Critical· 9.8SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API
CVE-2017-12617High· 8.1When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g
CVE-2017-11357Critical· 9.8Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
CVE-2017-12615High· 8.1When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g