All CVEs
Vulnerability intelligence

CVE-2025-52691

SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability

SmarterTools SmarterMail

Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.

CVSS Score
10
Critical
EPSS — Exploit Probability
86%
Riskier than 100% of all CVEs · checked 2026-09-06
Exploitation
Confirmed in the wild
Used in ransomware campaigns
Remediation
Unconfirmed
Federal deadline 2026-02-16
CISA required action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Deadline for federal agencies: 2026-02-16.

NVD entry CISA KEV

3 articles across 3 outlets · first covered Jan 27, 2026 · latest Feb 10, 2026

Coverage timeline

Related CVEs — SmarterTools