CVE-2025-52691 - SmarterMail unauthenticated arbitrary file upload
An unauthenticated attacker can upload arbitrary files to locations on the mail server, potentially enabling remote code execution.
Tags: file-upload, unauthenticated, rce, smartermail, exploited
- Product
- SmarterTools SmarterMail Build 9406 and earlier
- Severity
- critical (CVSS 10)
- Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H- Published / added
- 2025-12-29
- Signals
- CISA KEV