CVE-2025-52691: SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability

Critical severity, CVSS 10.0. Actively exploited: in CISA KEV since 2026-01-26. EPSS: 85.7% chance of exploitation in the next 30 days.

Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.

Affected products

  • SmarterTools SmarterMail: before 100.0.9413 (fixed in 100.0.9413)

Published 2025-12-29. Last modified 2026-10-07.