Known vulnerability record
CVE-2025-52691
SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability
Summary
SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability
SmarterTools SmarterMail contains an unrestricted upload of file with dangerous type vulnerability that could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.
Signals
Keep the signals separate
CVSS severitycriticalScore 10 · source CSA
EPSS probability85.5%Probability of exploitation in the next 30 days; not severity
CISA KEVKnown exploitedAdded 2026-01-26
Ransomware useknownPreserved as known / unknown, not a truthy default
Timeline
Dates and provenance
- CVE published
- 2025-12-29
- CVE modified
- 2026-02-26
- KEV date added
- 2026-01-26
- Dataset fetched
- 2026-08-21T03:55:02.945Z
Sources
Original records
- https://www.cve.org/CVERecord?id=CVE-2025-52691 ↗
- https://nvd.nist.gov/vuln/detail/CVE-2025-52691 ↗
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-52691 ↗
Version history: normalized permanent page created 2026-08-20. Machine-enriched fields remain source-attributed.