SmarterTools SmarterMail < build 9511 contains an unauthenticated remote code execution caused by malicious OS command execution via ConnectToHub API method, letting remote attackers execute arbitrary commands, exploit requires no authentication.
id: CVE-2026-24423
info:
name: SmarterMail - Remote Code Execution
author: jyoti369
severity:
...