INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

SmarterMail Ransomware Breaches Through Unpatched Server

| 2026-02-10 10:24 CRITICAL HIGH
Executive Summary AI-generated
The Warlock ransomware gang has breached SmarterTools' network by exploiting an unpatched SmarterMail instance, which is just one of several incidents that have highlighted the vulnerability of outdated software. The attack involved the abuse of CVE-2026-23760 to bypass authentication and stage the ransomware payload on internet-facing systems. This pace of weaponization suggests a rapid analysis of vendor fixes by operators, who are developing working tradecraft shortly after release. SmarterTools has advised users to upgrade to the latest version with immediate effect for optimal protection, while also isolating mail servers to block lateral movement attempts used to deploy ransomware. The incident serves as a reminder that cybersecurity is not just about patching vulnerabilities but also about staying ahead of attackers who rapidly analyze and exploit them.
Technical Mitigations AI-generated
* Ensure that SmarterMail instances are updated to the latest version, specifically build 9511 or higher, as soon as possible after discovering a vulnerability. * Implement a patching strategy for vulnerable systems and services, such as updating operating systems and software to the latest versions. * Monitor network traffic and system logs for signs of ransomware activity, and take immediate action if suspicious behavior is detected. * Use secure coding practices when developing applications that interact with SmarterMail, including following best practices for input validation and sanitization. * Consider implementing a two-factor authentication (2FA) or multi-factor authentication (MFA) protocol to add an extra layer of security against unauthorized access.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-23760CVE-2026-23760 CVE-2025-52691CVE-2025-52691 CVE-2026-24423CVE-2026-24423 CVE-2026-25067CVE-2026-25067
Target & Sectors
LA
Incident Timeline
January 15, 2026
Threat actors exploited an unpatched SmarterMail Server vulnerability to gain access to SmarterTools' Warlock Ransomware.
January 22, 2026
Threat actors exploited an unpatched SmarterMail Server vulnerability to gain access and infect the Warlock Ransomware.
January 29, 2026
SmarterMail servers were compromised through unpatched SmarterTools systems.
organisation SmarterTrack
organisation ReliaQuest
organisation Velociraptor
organisation The Hacker News
infrastructure Smartermail
infrastructure 30 servers
organisation CVE-2025-52691
infrastructure 10.0
infrastructure 9.3
organisation CVSS
organisation API
organisation CVE-2026
infrastructure Windows
infrastructure 12 Windows servers
organisation MSI
organisation Supabase
organisation the Active Directory
Jan 30, 2026
Threat actors used a known vulnerability in SmarterMail Server to gain unauthorized access and exploit an unpatched version of SmarterTools' software.
Jan 30
SmarterTools addressed two security flaws in SmarterMail email software, including a critical one that could result in arbitrary code execution.
infrastructure Smartermail
organisation SmarterMail
organisation SmarterTools
organisation Vulnerability / Email Security
2026-02-03
SmarterTools confirmed last week that the Warlock ransomware gang breached its network by exploiting an unpatched SmarterMail instance.
tactic Ransomware
infrastructure Smartermail
organisation SmarterMail
organisation SmarterTools
organisation Storm-2603
vulnerability CVE-2026-24423
attribution CISA
attribution CVE-2026
WT-2026-0001
Threat actors used SmarterMail Server vulnerabilities to target SmarterTools through unpatched SmarterMail servers.
vulnerability CVE-2026-24423
organisation los investigadores de relojTowr
organisation defecto de bypass de autenticación
2026-02-10
SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method.
infrastructure Smartermail
infrastructure Windows
organisation SmarterMail
organisation un
organisation La falla CVE-2026-24423
organisation remota de códigos
organisation El vendedor
organisation SmarterMail Build
organisation Desde
organisation el 30
organisation SmarterMail Fixes Critical Unauthenticated
organisation CVSS 9.3 Score
organisation CVE.org
organisation UNC
organisation Universal Naming Convention
organisation SMB
organisation CVSS
organisation básica de groupware.
organisation medianas empresas
organisation SmarterTools
organisation BOD
organisation las actualizaciones de seguridad
organisation dejar de utilizar el producto
organisation El defecto
organisation los registros de sistemas
organisation el camino de código
organisation aprenda
organisation la respuesta automatizada
infrastructure 9.3
organisation NTLM
organisation VulnCheck
organisation Cale Black
Tactical Metrics
Metrics
infrastructure
​Smartermail
Affected Product
Metrics
infrastructure
​Windows
Affected Product
Metrics
infrastructure
30
Servers
Metrics
infrastructure
12
Windows Servers
Metrics
infrastructure
​10.0
Software Version
Metrics
infrastructure
​9.3
Software Version
Intelligence Sources