CVE-2025-52691 SmarterMail Arbitrary File Upload RCE
Arbitrary file upload enabling unauthenticated remote code execution on SmarterMail email gateways without authentication, affecting all customer data and backend infrastructure.
-
SmarterTools SmarterMail CVE-2025-52691: Unauthenticated Arbitrary File Upload Enables Remote Code Execution on Email Gateways
SmarterTools SmarterMail CVE-2025-52691 (CVSS 10.0) allows unauthenticated attackers to upload arbitrary files to mail servers without authentication, enabling immediate remote code execution. Affects Build 9406 and earlier; patched in Build…
·
·
11–16 minutes

