smartertools has 2 CVEs on record. The median CVSS is 9.8 (critical), with 2 rated critical.
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 100% vs 1% corpus
- Median CVSS
- 9.8
- Publish → KEV
- —(2)
- Last 90 days
- 0 prev 0
2
Total CVEs
2
Critical
2
CISA KEV
2
Exploited
Worst active — by depth score
CVE-2026-24423Critical· 9.8SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method100CVE-2026-23760Critical· 9.8SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API100
smartertools vulnerabilities
CVEs affecting smartertools, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-24423Critical· 9.8CISA KEVPoCSmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method
SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the SmarterMail to the malicious HTTP server, which serves the …
▾ Hadalsmartertools · smartermailEPSS 88%via NVD
CVE-2026-23760Critical· 9.8CISA KEVPoCSmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API
SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a r…
▾ Hadalsmartertools · smartermailEPSS 97%via NVD