EXPOSURES › CVE-2025-52691
CVE-2025-52691
CRITICAL ⌖ ON CISA KEV · EXPLOITEDSmarterMail's unrestricted file upload flaw allowed attackers to upload malicious files and execute remote code on mail servers.
An unauthenticated attacker could upload arbitrary files to any location on the SmarterMail server, enabling remote code execution. This is a critical, actively exploited vulnerability linked to ransomware, meaning DIB organizations using SmarterMail face immediate compromise risks and must patch or replace the product urgently.
Shame score — The vendor shipped a product with a critical, actively exploited RCE flaw that attackers used for ransomware, indicating severe negligence in patching and secure design.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
SmarterTools SmarterMail contains an unrestricted upload of file with dangerous type vulnerability that could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.