CVE-2019-7212: SmarterTools SmarterMail

High severity, CVSS 8.2. EPSS: 1% chance of exploitation in the next 30 days.

SmarterTools SmarterMail 16.x before build 6985 has hardcoded secret keys. An unauthenticated attacker could access other users’ emails and file attachments. It was also possible to interact with mailing lists.

Affected products

  • SmarterTools SmarterMail: from 16.0.6345, before 16.3.6985 (fixed in 16.3.6985)

Published 2019-04-24. Last modified 2026-06-17.