SmarterTools A.I CyberSecurity Scoring
SmarterTools
Company Information
Website:https://www.smartertools.com/
Employees number:23
Number of followers:1,159
NAICS:5112
Industry Type:Software Development
Homepage:smartertools.com
SmarterTools Risk Score (AI oriented)
Between 0 and 549
SmarterToolsSoftware Development
Updated:
01/04/2026
01/04/2026
381/1000
Critical
C
SmarterTools Global Score (TPRM)
xxxx
SmarterToolsSoftware Development
Score locked

SmarterToolsCritical
Current Score
381C (CRITICAL)
01000
5 incidents
-78 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
426
AUGUST 2026
420
JULY 2026
413
JUNE 2026
404
MAY 2026
395
APRIL 2026
388
MARCH 2026
380
FEBRUARY 2026
627
Ransomware
06 Feb 2026 • SmarterTools
SmarterTools and Federal agencies: CISA Warns of Actively Exploited SmarterTools SmarterMail Vulnerability Used in Ransomware Attacks
CISA Warns of Actively Exploited SmarterMail Flaw in Ransomware Attacks
453
CRITICAL-174
SMASPI1770366900
CISA Warns of Actively Exploited SmarterMail Flaw in Ransomware Attacks
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert after adding CVE-2026-24423, a critical vulnerability in SmarterTools SmarterMail, to its Known Exploited Vulnerabilities (KEV) catalog. The flaw is being actively exploited in ransomware campaigns, posing a severe risk to mail server infrastructure globally.
The vulnerability stems from a Missing Authentication for Critical Function (CWE-306) weakness in SmarterMail’s ConnectToHub API method. Due to a programming oversight, unauthenticated attackers can remotely invoke the API, forcing a vulnerable SmarterMail instance to connect to an attacker-controlled server. Malicious responses containing OS commands are then executed with system-level privileges, enabling Remote Code Execution (RCE) and potential full compromise of the email environment.
Security researchers report that threat actors are leveraging this exploit to deploy privilege escalation tools, network discovery utilities, and ransomware payloads, encrypting files across enterprise networks. Email servers remain prime targets due to their sensitive data and role in lateral movement within corporate systems.
Federal agencies have been mandated to remediate the issue by February 26, 2026, though CISA strongly advises private organizations to patch immediately due to ongoing exploitation. SmarterTools has released a fix, and mitigations such as restricting API access via a Web Application Firewall (WAF) or isolating affected servers are recommended for organizations unable to patch immediately. If mitigations are unfeasible, CISA advises discontinuing use of vulnerable builds until secure updates are deployed.
Successful exploitation can lead to data exfiltration, operational disruption, and widespread ransomware deployment, underscoring the urgency of addressing this flaw.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JANUARY 2026
743
Ransomware
29 Jan 2026 • SmarterTools
SmarterTools and SmarterMail Customers: Warlock Gang Breaches SmarterTools Via SmarterMail Bugs
SmarterTools Breach Linked to Critical SmarterMail Vulnerabilities Exploited by Warlock Ransomware Group
627
CRITICAL-116
SMA1770688489
SmarterTools Breach Linked to Critical SmarterMail Vulnerabilities Exploited by Warlock Ransomware Group
SmarterTools, the vendor behind the SmarterMail email server, recently disclosed a breach stemming from two critical vulnerabilities in its own product. The flaws CVE-2026-24423 (an unauthenticated remote-code execution bug in the ConnectToHub API method) and CVE-2026-23760 (an authentication bypass enabling forced admin password resets) were patched in SmarterMail release 9511 on January 15, but not before being exploited by the China-based Warlock ransomware group.
The attack, which occurred on January 29, compromised SmarterTools’ internal network, including 12 Windows servers and a data center used for lab and quality control. While most Linux servers remained unaffected, the breach originated from a single unpatched SmarterMail instance among the company’s 30 deployed servers. The threat actors leveraged the vulnerabilities to redirect SmarterMail instances to a malicious server, execute commands, and eventually gain control of Active Directory installing files and waiting up to a week before deploying ransomware.
SmarterTools’ COO, Derek Curtis, confirmed that the company’s office network and a secondary data center were impacted, though business applications and customer data remained secure due to network isolation. The company responded by shutting down all servers, disabling internet access, and restructuring networks eliminating Windows dependencies where possible and resetting all passwords. SentinelOne assisted in detecting the intrusion and preventing encryption.
While no major security issues currently affect SmarterMail, Curtis acknowledged that some customers were breached before patches were applied, as initial compromises predated visible evidence. The Warlock group’s tactics included Active Directory takeover, lateral movement, and delayed ransomware execution, mirroring attacks observed on customer systems.
SmarterTools serves SMBs and enterprises as an alternative to Microsoft Exchange, making these vulnerabilities particularly high-risk. Both CVEs carry a critical CVSS score of 9.3, underscoring the severity of the flaws. The company has since committed to improved transparency in security communications, though it has not yet responded to inquiries about lessons learned. Customers were urged to update to the patched version and investigate potential breaches using provided indicators of compromise.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
JANUARY 2026
748
Vulnerability
26 Jan 2026 • SmarterTools
SmarterTools: 6,000+ SmarterMail Servers Exposed to Actively Exploited RCE Vulnerability
Critical SmarterMail RCE Vulnerability Under Active Exploitation
743
CRITICAL-5
SMA1769518747
Critical SmarterMail RCE Vulnerability Under Active Exploitation
A severe remote code execution (RCE) vulnerability in SmarterTools’ SmarterMail software is being actively exploited, exposing thousands of servers worldwide. Tracked as CVE-2026-23760, the flaw allows unauthenticated attackers to execute arbitrary commands on vulnerable systems, granting full control over affected servers.
Security researchers identified approximately 6,000 internet-accessible SmarterMail instances running unpatched versions, with exploitation attempts already confirmed in the wild. The Shadowserver Foundation detected the threat through version-based scans, revealing a broad attack surface across enterprises, educational institutions, and service providers.
The vulnerability poses significant risks, including email interception, malware deployment, and persistent backdoor access. Organizations in healthcare, finance, government, and technology sectors are among those likely affected, given SmarterMail’s widespread adoption. Successful exploitation could lead to data exfiltration, business email compromise (BEC), and supply chain attacks.
SmarterTools has released patches to address CVE-2026-23760, classified as critical due to its severity and active exploitation. The flaw’s global distribution underscores the urgency for organizations to assess, patch, and monitor their deployments to mitigate potential breaches.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
DECEMBER 2025
751
Vulnerability
29 Dec 2025 • SmarterTools
SmarterTools: Update NOW! Singaporean government and cyber security firm warn of perfect 10 SmarterTools vulnerability
CVE-2025-52691: Pre-Auth RCE in SmarterTools’ SmarterMail
748
CRITICAL-3
SMA1768202332
Critical RCE Vulnerability in SmarterMail Exposes Servers to Exploitation
A severe pre-authentication remote code execution (RCE) flaw in SmarterTools’ SmarterMail a widely used business email and collaboration platform has raised alarms among cybersecurity experts and government agencies. Tracked as CVE-2025-52691 and assigned a CVSS score of 10, the vulnerability allows unauthenticated attackers to upload arbitrary files to vulnerable servers, potentially leading to full system compromise.
The flaw was disclosed on December 29, 2025, in a joint effort between SmarterTools and the Cyber Security Agency of Singapore (CSA), which urged users to immediately update to Build 9413. Despite the patch’s availability since October 2025, the delayed public disclosure left systems exposed for nearly three months. Evidence of exploitation attempts surfaced in early January 2025, with forum discussions highlighting malicious scripts designed to chain attacks via PowerShell for full server takeover.
Security researchers, including Benjamin Harris of watchTowr, criticized SmarterTools’ "silent patching" approach, which withheld public advisories until late December. This strategy allowed threat actors to reverse-engineer the fix and target uninformed administrators. Many users only learned of the vulnerability after its disclosure, raising concerns about the company’s communication practices.
Administrators running versions prior to Build 9413 between October and December 2025 are advised to review logs for suspicious file uploads or anomalous activity, as the lack of timely warnings left systems vulnerable to undetected breaches. The incident underscores the risks of delayed disclosures in critical software vulnerabilities.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
NOVEMBER 2025
751
Breach
12 Nov 2025 • SmarterTools
Shinhan Card: Shinhan Card reports data breach involving 190,000 merchant records
Shinhan Card Personal Data Breach Involving Merchant Representatives
659
HIGH-92
SHI1766477260
Shinhan Card Reports Data Breach Affecting 190,000 Merchant Representatives
Shinhan Card disclosed a data breach involving approximately 192,088 records of merchant representatives, marking the latest in a series of recent leaks affecting major South Korean firms, including Coupang, KT, SK Telecom, and Lotte Card. The incident, reported to the Personal Information Protection Commission (PIPC) on Tuesday, was attributed to internal employee misconduct related to new card solicitation rather than external hacking.
The exposed data included:
- 181,585 records containing only mobile phone numbers
- 8,120 records with phone numbers and names
- 2,310 records with phone numbers, names, birth years, and gender
- 73 records with phone numbers, names, and full dates of birth
Shinhan Card confirmed that no highly sensitive information—such as resident registration numbers, card details, or bank accounts—was compromised. The breach was limited to merchant representatives, with no impact on individual cardholders. The company stated that the leak stemmed from isolated employee actions and posed no further dissemination risk.
The case came to light after a whistleblower submitted evidence to the PIPC, prompting an investigation. Shinhan Card began reviewing the allegations on November 13, verifying the breach through internal records. Following the findings, the company issued a public apology, notified affected merchants, and launched a webpage for individuals to check their exposure.
While Shinhan Card has taken measures equivalent to those for a data breach, further review is needed to classify the incident officially. The company pledged to strengthen protections to prevent future occurrences.
Security Investment Trends Lag Despite Rising Breaches
A recent survey by market tracker Leaders Index revealed that while major South Korean firms increased IT spending by 31.2% (from 16.5 trillion won in 2022 to 21.6 trillion won in 2024), information security investment grew only marginally in proportion—from 5.8% to 5.9% of total IT budgets. Security staffing saw a similar trend, with dedicated personnel rising 22.3% but remaining at just 6.7% of IT workforce share. Analysts noted that despite absolute increases, security priorities continue to trail broader technology spending.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
OCTOBER 2025
751
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for SmarterTools ??
What was SmarterTools's A.I Rankiteo Cyber Score in August 2026 ??
What was SmarterTools's A.I Rankiteo Cyber Score in July 2026 ??
What was SmarterTools's A.I Rankiteo Cyber Score in June 2026 ??
What was SmarterTools's A.I Rankiteo Cyber Score in May 2026 ??
What was SmarterTools's A.I Rankiteo Cyber Score in April 2026 ??
What was SmarterTools's A.I Rankiteo Cyber Score in March 2026 ??
What was SmarterTools's A.I Rankiteo Cyber Score in February 2026 ??
What was SmarterTools's A.I Rankiteo Cyber Score in January 2026 ??
What was SmarterTools's A.I Rankiteo Cyber Score in December 2025 ??
What was SmarterTools's A.I Rankiteo Cyber Score in November 2025 ??
What was SmarterTools's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on SmarterTools's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with SmarterTools ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view SmarterTools's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?