Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
SmarterTools

SmarterTools Vendor Cyber Rating & Cyber Score

smartertools.com

Founded in 2003, SmarterTools Inc. is an information technology management software company that builds applications to help companies communicate, measure, and support their worldwide business operations. SmarterTools products serve thousands of companies across the globe in a broad base of market segments—including those in the technology, financial, education, and hosting industries. Today, SmarterTools has more than 15 million end users and a strong, global network of channel partnerships. In addition, SmarterTools has targeted various small and enterprise-level businesses, Web hosts, and service providers to grow its install base to include customers in more than 100 countries. With industry-leading products, a strong financial


SmarterTools A.I CyberSecurity Scoring

SmarterTools
Company Information
Website:https://www.smartertools.com/
Employees number:23
Number of followers:1,159
NAICS:5112
Industry Type:Software Development
Homepage:smartertools.com
SmarterTools Risk Score (AI oriented)
Between 0 and 549
logo
SmarterToolsSoftware Development
Updated:
01/04/2026
381/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
SmarterTools Global Score (TPRM)
xxxx
logo
SmarterToolsSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

SmarterTools
SmarterToolsCritical
Current Score
381C (CRITICAL)
01000
5 incidents
-78 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
426Before Incident
AUGUST 2026
420Before Incident
JULY 2026
413Before Incident
JUNE 2026
404Before Incident
MAY 2026
395Before Incident
APRIL 2026
388Before Incident
MARCH 2026
380Before Incident
FEBRUARY 2026
627Before Incident
Ransomware
06 Feb 2026SmarterTools
SmarterTools and Federal agencies: CISA Warns of Actively Exploited SmarterTools SmarterMail Vulnerability Used in Ransomware Attacks

CISA Warns of Actively Exploited SmarterMail Flaw in Ransomware Attacks

453After Incident
CRITICAL-174
SMASPI1770366900
CISA Warns of Actively Exploited SmarterMail Flaw in Ransomware Attacks The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert after adding CVE-2026-24423, a critical vulnerability in SmarterTools SmarterMail, to its Known Exploited Vulnerabilities (KEV) catalog. The flaw is being actively exploited in ransomware campaigns, posing a severe risk to mail server infrastructure globally. The vulnerability stems from a Missing Authentication for Critical Function (CWE-306) weakness in SmarterMail’s ConnectToHub API method. Due to a programming oversight, unauthenticated attackers can remotely invoke the API, forcing a vulnerable SmarterMail instance to connect to an attacker-controlled server. Malicious responses containing OS commands are then executed with system-level privileges, enabling Remote Code Execution (RCE) and potential full compromise of the email environment. Security researchers report that threat actors are leveraging this exploit to deploy privilege escalation tools, network discovery utilities, and ransomware payloads, encrypting files across enterprise networks. Email servers remain prime targets due to their sensitive data and role in lateral movement within corporate systems. Federal agencies have been mandated to remediate the issue by February 26, 2026, though CISA strongly advises private organizations to patch immediately due to ongoing exploitation. SmarterTools has released a fix, and mitigations such as restricting API access via a Web Application Firewall (WAF) or isolating affected servers are recommended for organizations unable to patch immediately. If mitigations are unfeasible, CISA advises discontinuing use of vulnerable builds until secure updates are deployed. Successful exploitation can lead to data exfiltration, operational disruption, and widespread ransomware deployment, underscoring the urgency of addressing this flaw.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gainData exfiltration
IMPACT
Data Compromised: Sensitive data from email serversSystems Affected: SmarterMail email serversOperational Impact: Operational disruption
DATA BREACH
Type Of Data Compromised: Sensitive email dataSensitivity Of Data: High
JANUARY 2026
743Before Incident
Ransomware
29 Jan 2026SmarterTools
SmarterTools and SmarterMail Customers: Warlock Gang Breaches SmarterTools Via SmarterMail Bugs

SmarterTools Breach Linked to Critical SmarterMail Vulnerabilities Exploited by Warlock Ransomware Group

627After Incident
CRITICAL-116
SMA1770688489
SmarterTools Breach Linked to Critical SmarterMail Vulnerabilities Exploited by Warlock Ransomware Group SmarterTools, the vendor behind the SmarterMail email server, recently disclosed a breach stemming from two critical vulnerabilities in its own product. The flaws CVE-2026-24423 (an unauthenticated remote-code execution bug in the ConnectToHub API method) and CVE-2026-23760 (an authentication bypass enabling forced admin password resets) were patched in SmarterMail release 9511 on January 15, but not before being exploited by the China-based Warlock ransomware group. The attack, which occurred on January 29, compromised SmarterTools’ internal network, including 12 Windows servers and a data center used for lab and quality control. While most Linux servers remained unaffected, the breach originated from a single unpatched SmarterMail instance among the company’s 30 deployed servers. The threat actors leveraged the vulnerabilities to redirect SmarterMail instances to a malicious server, execute commands, and eventually gain control of Active Directory installing files and waiting up to a week before deploying ransomware. SmarterTools’ COO, Derek Curtis, confirmed that the company’s office network and a secondary data center were impacted, though business applications and customer data remained secure due to network isolation. The company responded by shutting down all servers, disabling internet access, and restructuring networks eliminating Windows dependencies where possible and resetting all passwords. SentinelOne assisted in detecting the intrusion and preventing encryption. While no major security issues currently affect SmarterMail, Curtis acknowledged that some customers were breached before patches were applied, as initial compromises predated visible evidence. The Warlock group’s tactics included Active Directory takeover, lateral movement, and delayed ransomware execution, mirroring attacks observed on customer systems. SmarterTools serves SMBs and enterprises as an alternative to Microsoft Exchange, making these vulnerabilities particularly high-risk. Both CVEs carry a critical CVSS score of 9.3, underscoring the severity of the flaws. The company has since committed to improved transparency in security communications, though it has not yet responded to inquiries about lessons learned. Customers were urged to update to the patched version and investigate potential breaches using provided indicators of compromise.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain (ransomware deployment)
IMPACT
Systems Affected: 12 Windows servers, internal network, data center (lab and quality control)Operational Impact: Network shutdown, internet access disabled, network restructuringBrand Reputation Impact: High (critical vulnerabilities, delayed patching, customer breaches)
JANUARY 2026
748Before Incident
Vulnerability
26 Jan 2026SmarterTools
SmarterTools: 6,000+ SmarterMail Servers Exposed to Actively Exploited RCE Vulnerability

Critical SmarterMail RCE Vulnerability Under Active Exploitation

743After Incident
CRITICAL-5
SMA1769518747
Critical SmarterMail RCE Vulnerability Under Active Exploitation A severe remote code execution (RCE) vulnerability in SmarterTools’ SmarterMail software is being actively exploited, exposing thousands of servers worldwide. Tracked as CVE-2026-23760, the flaw allows unauthenticated attackers to execute arbitrary commands on vulnerable systems, granting full control over affected servers. Security researchers identified approximately 6,000 internet-accessible SmarterMail instances running unpatched versions, with exploitation attempts already confirmed in the wild. The Shadowserver Foundation detected the threat through version-based scans, revealing a broad attack surface across enterprises, educational institutions, and service providers. The vulnerability poses significant risks, including email interception, malware deployment, and persistent backdoor access. Organizations in healthcare, finance, government, and technology sectors are among those likely affected, given SmarterMail’s widespread adoption. Successful exploitation could lead to data exfiltration, business email compromise (BEC), and supply chain attacks. SmarterTools has released patches to address CVE-2026-23760, classified as critical due to its severity and active exploitation. The flaw’s global distribution underscores the urgency for organizations to assess, patch, and monitor their deployments to mitigate potential breaches.
INCIDENT DETAILS -
TYPE
Remote Code Execution (RCE)
IMPACT
Data Compromised: Email interception, data exfiltrationSystems Affected: SmarterMail serversOperational Impact: Full control over affected servers, potential business email compromise (BEC), supply chain attacks
DATA BREACH
Type Of Data Compromised: Email data, sensitive business informationSensitivity Of Data: HighData Exfiltration: Possible
DECEMBER 2025
751Before Incident
Vulnerability
29 Dec 2025SmarterTools
SmarterTools: Update NOW! Singaporean government and cyber security firm warn of perfect 10 SmarterTools vulnerability

CVE-2025-52691: Pre-Auth RCE in SmarterTools’ SmarterMail

748After Incident
CRITICAL-3
SMA1768202332
Critical RCE Vulnerability in SmarterMail Exposes Servers to Exploitation A severe pre-authentication remote code execution (RCE) flaw in SmarterTools’ SmarterMail a widely used business email and collaboration platform has raised alarms among cybersecurity experts and government agencies. Tracked as CVE-2025-52691 and assigned a CVSS score of 10, the vulnerability allows unauthenticated attackers to upload arbitrary files to vulnerable servers, potentially leading to full system compromise. The flaw was disclosed on December 29, 2025, in a joint effort between SmarterTools and the Cyber Security Agency of Singapore (CSA), which urged users to immediately update to Build 9413. Despite the patch’s availability since October 2025, the delayed public disclosure left systems exposed for nearly three months. Evidence of exploitation attempts surfaced in early January 2025, with forum discussions highlighting malicious scripts designed to chain attacks via PowerShell for full server takeover. Security researchers, including Benjamin Harris of watchTowr, criticized SmarterTools’ "silent patching" approach, which withheld public advisories until late December. This strategy allowed threat actors to reverse-engineer the fix and target uninformed administrators. Many users only learned of the vulnerability after its disclosure, raising concerns about the company’s communication practices. Administrators running versions prior to Build 9413 between October and December 2025 are advised to review logs for suspicious file uploads or anomalous activity, as the lack of timely warnings left systems vulnerable to undetected breaches. The incident underscores the risks of delayed disclosures in critical software vulnerabilities.
INCIDENT DETAILS -
TYPE
Remote Code Execution (RCE)
IMPACT
Systems Affected: SmarterMail business email and collaboration serversOperational Impact: Potential full server compromise (RCE)Brand Reputation Impact: Erosion of trust due to silent patching and lack of clear communication
NOVEMBER 2025
751Before Incident
Breach
12 Nov 2025SmarterTools
Shinhan Card: Shinhan Card reports data breach involving 190,000 merchant records

Shinhan Card Personal Data Breach Involving Merchant Representatives

659After Incident
HIGH-92
SHI1766477260
Shinhan Card Reports Data Breach Affecting 190,000 Merchant Representatives Shinhan Card disclosed a data breach involving approximately 192,088 records of merchant representatives, marking the latest in a series of recent leaks affecting major South Korean firms, including Coupang, KT, SK Telecom, and Lotte Card. The incident, reported to the Personal Information Protection Commission (PIPC) on Tuesday, was attributed to internal employee misconduct related to new card solicitation rather than external hacking. The exposed data included: - 181,585 records containing only mobile phone numbers - 8,120 records with phone numbers and names - 2,310 records with phone numbers, names, birth years, and gender - 73 records with phone numbers, names, and full dates of birth Shinhan Card confirmed that no highly sensitive information—such as resident registration numbers, card details, or bank accounts—was compromised. The breach was limited to merchant representatives, with no impact on individual cardholders. The company stated that the leak stemmed from isolated employee actions and posed no further dissemination risk. The case came to light after a whistleblower submitted evidence to the PIPC, prompting an investigation. Shinhan Card began reviewing the allegations on November 13, verifying the breach through internal records. Following the findings, the company issued a public apology, notified affected merchants, and launched a webpage for individuals to check their exposure. While Shinhan Card has taken measures equivalent to those for a data breach, further review is needed to classify the incident officially. The company pledged to strengthen protections to prevent future occurrences. Security Investment Trends Lag Despite Rising Breaches A recent survey by market tracker Leaders Index revealed that while major South Korean firms increased IT spending by 31.2% (from 16.5 trillion won in 2022 to 21.6 trillion won in 2024), information security investment grew only marginally in proportion—from 5.8% to 5.9% of total IT budgets. Security staffing saw a similar trend, with dedicated personnel rising 22.3% but remaining at just 6.7% of IT workforce share. Analysts noted that despite absolute increases, security priorities continue to trail broader technology spending.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
New Card Solicitation (Non-Malicious)
IMPACT
Data Compromised: 192,088 recordsBrand Reputation Impact: YesIdentity Theft Risk: Low (No highly sensitive data exposed)Payment Information Risk: None (No card or bank details compromised)
DATA BREACH
Mobile phone numbersNamesYear of birthGenderFull dates of birthNumber Of Records Exposed: 192,088Sensitivity Of Data: Low to Moderate (No resident registration numbers, card numbers, or bank details)Data Exfiltration: No evidence of further disseminationPersonally Identifiable Information: Yes (Phone numbers, names, dates of birth)
OCTOBER 2025
751Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for SmarterTools ?
?
What was SmarterTools's A.I Rankiteo Cyber Score in August 2026 ?
?
What was SmarterTools's A.I Rankiteo Cyber Score in July 2026 ?
?
What was SmarterTools's A.I Rankiteo Cyber Score in June 2026 ?
?
What was SmarterTools's A.I Rankiteo Cyber Score in May 2026 ?
?
What was SmarterTools's A.I Rankiteo Cyber Score in April 2026 ?
?
What was SmarterTools's A.I Rankiteo Cyber Score in March 2026 ?
?
What was SmarterTools's A.I Rankiteo Cyber Score in February 2026 ?
?
What was SmarterTools's A.I Rankiteo Cyber Score in January 2026 ?
?
What was SmarterTools's A.I Rankiteo Cyber Score in December 2025 ?
?
What was SmarterTools's A.I Rankiteo Cyber Score in November 2025 ?
?
What was SmarterTools's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on SmarterTools's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with SmarterTools ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view SmarterTools's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?