Vulnerabilidades em SmarterTools
10 resultadosAnálise Vexday
SmarterTools apresenta 9 vulnerabilidades catalogadas, com 3 delas sob exploração ativa em ambientes reais (KEV), representando um risco concreto e imediato. As 4 vulnerabilidades críticas associadas predominantemente a falhas de validação (CWE-79 - XSS) indicam exposição a ataques direcionados, embora o panorama esteja estabilizado sem novas publicações nos últimos 90 dias.
CVE-2026-23760CRITICALSmarterTools SmarterMail < Build 9511 Authentication Bypass via Password Reset APIEPSS 96.3%KEVCVE-2026-24423CRITICALSmarterTools SmarterMail < Build 9511 Unauthenticated RCE via ConnectToHub APIEPSS 87.7%KEVCVE-2025-52691CRITICALUpload Arbitrary FilesEPSS 85.5%KEVCVE-2022-24384HIGHReflective XSS on SmarterTrack v100.0.8019.14010EPSS 4.7%CVE-2022-24387CRITICALFile upload and overwrite to app_data/Config in SmarterTrack v100.0.8019.14010EPSS 2.1%CVE-2022-24385MEDIUMInformation disclosure via direct object access on SmarterTrack v100.0.8019.14010EPSS 0.9%CVE-2022-24386HIGHStored XSS in SmarterTrack v100.0.8019.14010EPSS 0.7%CVE-2020-36926MEDIUMSmarterTools SmarterTrack 7922 -Information DisclosureEPSS 0.5%CVE-2026-26930HIGHSmarterTools SmarterMail before 9526 allows XSS via MAPI requests.EPSS 0.3%CVE-2026-25067MEDIUMSmarterTools SmarterMail < Build 9518 Unauthenticated background-of-the-day Path CoercionEPSS 0.3%