Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Feb 16, 2026

CVE-2025-52691

High
EPSS 79.9%CISA KEV
SmarterTools/SmarterMail

Description

SmarterTools SmarterMail contains an unrestricted upload of file with dangerous type vulnerability that could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.

EPSS — Exploit Probability

79.9%

Higher than 99.1% of all CVEs

Required Action

https://www.smartertools.com/smartermail/release-notes/current ; https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2025-124/ ; https://nvd.nist.gov/vuln/detail/CVE-2025-52691

Risk Assessment

HIGH
In CISA KEV
High EPSS

Details

Severity
High
EPSS
79.9%
CISA KEV
Yes
Ransomware
Unknown
Articles
1

Timeline

Published

Jan 26, 2026

Added to KEV

Jan 26, 2026

Remediation Due

Feb 16, 2026

Affected Product

SmarterTools

SmarterMail

View all SmarterTools CVEs