SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the SmarterMail to the malicious HTTP server, which serves the malicious OS command. This command will be executed by the vulnerable application.
Is CVE-2026-24423 exploited?
Listed in the CISA KEV catalog on 2026-02-05.
Federal remediation due 2026-02-26.
Past that date by 170 days.
Used in ransomware campaigns.
EPSS puts exploitation in the next 30 days at 88%.
Public exploit code: none found in monitored sources.
Public detection rules exist.
Which products and versions are affected?
No affected package list recorded here yet.
Is there a patch?
No patch identifier recorded here yet.
What PlainSec published about CVE-2026-24423
PlainSec has not published a story about this CVE.