CVE-2026-26930: SmarterTools SmarterMail
High severity, CVSS 7.2. EPSS: 0.4% chance of exploitation in the next 30 days.
SmarterTools SmarterMail before 9526 allows XSS via MAPI requests.
Affected products
- SmarterTools SmarterMail: before 9526 (fixed in 9526)
Published 2026-02-16. Last modified 2026-06-17.