CISA Known Exploited Vulnerability
This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.
Remediation Deadline: Feb 16, 2026
Description
SmarterTools SmarterMail contains an unrestricted upload of file with dangerous type vulnerability that could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.
EPSS — Exploit Probability
79.9%
Higher than 99.1% of all CVEs
Required Action
https://www.smartertools.com/smartermail/release-notes/current ; https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2025-124/ ; https://nvd.nist.gov/vuln/detail/CVE-2025-52691
Risk Assessment
HIGHIn CISA KEV
High EPSS
Details
- Severity
- High
- EPSS
- 79.9%
- CISA KEV
- Yes
- Ransomware
- Unknown
- Articles
- 1
Timeline
Published
Jan 26, 2026
Added to KEV
Jan 26, 2026
Remediation Due
Feb 16, 2026