Skip to content
COOEY

EXPOSURES › CVE-2025-52691

CVE-2025-52691

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-01-26 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-52691 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwarerceexploited-in-wildunpatched

SmarterMail's unrestricted file upload flaw allowed attackers to upload malicious files and execute remote code on mail servers.

An unauthenticated attacker could upload arbitrary files to any location on the SmarterMail server, enabling remote code execution. This is a critical, actively exploited vulnerability linked to ransomware, meaning DIB organizations using SmarterMail face immediate compromise risks and must patch or replace the product urgently.

Shame score — The vendor shipped a product with a critical, actively exploited RCE flaw that attackers used for ransomware, indicating severe negligence in patching and secure design.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

SmarterTools SmarterMail contains an unrestricted upload of file with dangerous type vulnerability that could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.