
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-52691 is a critical unrestricted file upload vulnerability (CWE-434) in SmarterTools SmarterMail that allows unauthenticated attackers to upload arbitrary files to any location on the mail server, potentially enabling remote code execution. It affects all SmarterMail versions prior to Build 100.0.9413 (including legacy Build 16.x up to 16.3.6989.16341). The vulnerability was first published on December 28–29, 2025, assigned by Singapore's Cyber Security Agency (CSA), and added to CISA's Known Exploited Vulnerabilities (KEV) catalog on January 26, 2026. It carries a CVSS v3.1 base score of 10.0 (Critical) (CSA Advisory, CISA KEV).
The root cause is an unrestricted file upload flaw (CWE-434) in SmarterMail's web interface that fails to validate or restrict file types and destination paths for uploaded content. Attackers exploit a path traversal condition in an unauthenticated endpoint to write arbitrary files — including ASPX web shells — to sensitive directories such as C:\Program Files (x86)\SmarterTools\SmarterMail\Service\App_Data (builds 94xx) or C:\Program Files (x86)\SmarterTools\SmarterMail\MRS\App_Data (build 16). No authentication, user interaction, or special privileges are required; the attack is fully network-accessible with low complexity. watchTowr researchers (Piotr @chudyPB and Sina Kheirkhah @SinSinology) published a detection artifact generator and technical write-up, and a separate authentication bypass (WT-2026-0001) was later disclosed that chains with this vulnerability for full account takeover leading to RCE (watchTowr PoC, watchTowr Blog).
Successful exploitation grants an unauthenticated remote attacker full control over the SmarterMail server, including the ability to execute arbitrary code as the mail service account, access all hosted email data, and use the compromised server as a pivot point for lateral movement within the network. The changed scope (S:C) in the CVSS vector reflects that impact extends beyond the mail application itself to the underlying host OS. Ransomware groups including Warlock (Storm-2603) and Medusa (Storm-1175) have leveraged this vulnerability to breach organizations, encrypt data, and extort victims (The Hacker News, Microsoft Blog, Huntress).
CVE-2025-52691 is actively exploited in the wild and was added to CISA's KEV catalog on January 26, 2026, with a remediation due date of February 16, 2026 (CISA KEV). Multiple public PoC exploits exist, including a Metasploit module (smartermail_guid_file_upload.rb) added January 22, 2026, the watchTowr detection tool, and several GitHub PoCs (Metasploit Module, watchTowr PoC). Exploitation was observed within days of patch release, with over 6,000–8,000 internet-exposed SmarterMail hosts identified as vulnerable; threat actors attributed include Warlock ransomware (Storm-2603), Medusa ransomware affiliate Storm-1175, and MuddyWater-style actors targeting Middle East critical sectors (BleepingComputer, Microsoft Blog). The EPSS score is approximately 0.233% as of initial publication, though real-world exploitation rates are significantly higher given active campaigns.
App_Data folder accessible via the web server).http://target/App_Data/shell.aspx) to execute arbitrary OS commands as the SmarterMail service account.../, ..\); outbound connections from the SmarterMail server to unknown external IPs; mass scanning activity targeting SmarterMail version enumeration endpoints..aspx files in C:\Program Files (x86)\SmarterTools\SmarterMail\Service\App_Data\ or C:\Program Files (x86)\SmarterTools\SmarterMail\MRS\App_Data\; newly created files with random names (e.g., epoyn5_0.aspx) in web-accessible directories; ransomware encryptor binaries or batch scripts dropped on the host..aspx files; Windows Event Logs showing new scheduled tasks or service installations by the SmarterMail service account.cmd.exe, powershell.exe, net.exe); w3wp.exe spawning command-line tools; unexpected aspnet_compiler.exe or csc.exe activity.SmarterTools released a patch in SmarterMail Build 100.0.9413; all installations running Build 9406 or earlier (including legacy Build 16.x) should be updated immediately (CISA KEV, SmarterTools Release Notes). As an interim workaround, implement network-level access controls to restrict internet-facing exposure of SmarterMail web interfaces to trusted IP ranges only. Monitor SmarterMail servers for suspicious file creation in App_Data directories and unexpected ASPX files. Conduct forensic analysis on potentially compromised systems to detect unauthorized file uploads or web shells before applying the patch. CISA's BOD 22-01 requires federal agencies to remediate by February 16, 2026.
Singapore's Cyber Security Agency (CSA) was the CVE assigner and issued an early alert (AL-2025-124), prompting rapid coverage from The Hacker News, BleepingComputer, TechRadar, and Security Affairs (CSA Advisory, The Hacker News). watchTowr researchers published a detailed technical write-up and PoC, noting the vulnerability was exploited in the wild just two days after a related patch was released (watchTowr Blog). Huntress documented real-world account takeover incidents leading to RCE, and Rapid7 added a Metasploit module with a wrap-up blog post (Huntress, Rapid7). The Warlock ransomware group notably breached SmarterTools itself through an unpatched SmarterMail server, generating significant media attention and community discussion on Reddit, Mastodon, and Bluesky (The Hacker News).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."