CVE-2026-23760Critical· 9.8▾ Hadal⚠ Exploited in the wildSmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a r…
▾ Hadal zone — Critical and actively exploited (CISA KEV / 0day)
impact 53.9 · likelihood 19.3 · exploitation 25 · ransomware 5
The latest CVEs are free to read. CVE-2026-23760 is outside the free window — sign in (free) to view the full technical detail, affected versions, references, and raw markdown.