SmarterMail CVE-2026-23760 Exploited for RCE via System Events

https://thecyberedition.com/smartermail-cve-2026-23760-exploited-for-rce-via-system-events/

Comments

thehacknewsJan 26, 2026, 4:51 AM
Attackers are actively abusing a SmarterMail account takeover flaw to gain admin access and pivot into remote code execution using System Events.

The intrusion chain uses automated API calls for password reset, token-based login, event-hook creation, and domain actions to trigger command execution and cleanup.