CVSS v3.1 Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS Prediction
Documented as more likely to be exploited than 99.1% of known CVEs.
Jan 26, 2026
Feb 16, 2026
Threat Analysis
SmarterTools SmarterMail contains an unrestricted upload of file with dangerous type vulnerability that could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.
Remediation Directive
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
External Intelligence
https://www.smartertools.com/smartermail/release-notes/current
https://www.smartertools.com/smartermail/release-notes/current
https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2025-124/
https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2025-124/
National Vulnerability Database
https://nvd.nist.gov/vuln/detail/CVE-2025-52691