Vulnerability intelligence
CVE-2025-52691
SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability
SmarterTools SmarterMail
Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.
CVSS Score
10
Critical
EPSS — Exploit Probability
86%
Riskier than 100% of all CVEs · checked 2026-09-06
Exploitation
Confirmed in the wild
Used in ransomware campaigns
Remediation
Unconfirmed
Federal deadline 2026-02-16
CISA required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Deadline for federal agencies: 2026-02-16.
3 articles across 3 outlets · first covered Jan 27, 2026 · latest Feb 10, 2026
Coverage timeline
-
Warlock Ransomware Breaches SmarterTools Through Unpatched SmarterMail Serverthehackernews.com · Feb 10, 2026
-
SmarterTools Hit by Ransomware via Vulnerability in Its Own Productwww.securityweek.com · Feb 9, 2026
-