CVE-2026-24423
CRITICAL(9.8)KEV — Aktiv ausgenutztCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CVSS 9.8 — Kritisch
- EPSS 88% — sehr wahrscheinlich ausgenutzt
- Im CISA KEV-Katalog (aktiv ausgenutzt)
CISA KEV
Bestätigt ausgenutzt
EPSS-Score
87.7%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
9.8
Technische Schwere
SecBoard-Einordnung
CVE-2026-24423 betrifft SmarterTools SmarterMail-Versionen vor Build 9511 und ist eine kritische Schwachstelle, die eine nicht authentifizierte Remote Code Execution (RCE) ermöglicht. Angreifer können über die ConnectToHub API-Methode bösartige OS-Befehle ausführen, indem sie SmarterMail auf einen präparierten HTTP-Server umleiten. Dies führt zur Ausführung der Befehle durch die anfällige Anwendung.
KI-gestützte Einordnung auf Basis der NVD-Daten.
Beschreibung
SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the SmarterMail to the malicious HTTP server, which serves the malicious OS command. This command will be executed by the vulnerable application.
Referenzen
- https://code-white.com/public-vulnerability-list/#systemadminsettingscontrollerc...
- https://www.smartertools.com/smartermail/release-notes/current
- https://www.vulncheck.com/advisories/smartertools-smartermail-unauthenticated-rc...
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-...