CVE-2026-24423: listed in the CISA KEV catalog

CVE-2026-24423 · CVSS 9.8 CRITICAL · EPSS 88% · KEV 2026-02-05

SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the SmarterMail to the malicious HTTP server, which serves the malicious OS command. This command will be executed by the vulnerable application.

Is CVE-2026-24423 exploited?

Which products and versions are affected?

No affected package list recorded here yet.

Is there a patch?

No patch identifier recorded here yet.

What PlainSec published about CVE-2026-24423

PlainSec has not published a story about this CVE.

Primary sources

What this record does not say

KEV and EPSS are re-checked daily. Record last updated 2026-08-11.