Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Feb 16, 2026

CVE-2026-23760

High
EPSS 65.4%CISA KEVRansomware
SmarterTools/SmarterMail

Description

SmarterTools SmarterMail contains an authentication bypass using an alternate path or channel vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts. This could allow an unauthenticated attacker to supply a target administrator username and a new password to reset the account, resulting in full administrative compromise of the SmarterMail instance.

EPSS — Exploit Probability

65.4%

Higher than 98.5% of all CVEs

Required Action

https://www.smartertools.com/smartermail/release-notes/current ; https://nvd.nist.gov/vuln/detail/CVE-2026-23760

Risk Assessment

CRITICAL
In CISA KEV
High EPSS
Ransomware

Details

Severity
High
EPSS
65.4%
CISA KEV
Yes
Ransomware
Known
Articles
0

Timeline

Published

Jan 26, 2026

Added to KEV

Jan 26, 2026

Remediation Due

Feb 16, 2026

Affected Product

SmarterTools

SmarterMail

View all SmarterTools CVEs