CVE-2026-24423: SmarterMail ConnectToHub API Exposes Servers to Unauthenticated Remote Code Execution
CVE-2026-24423 is a missing authentication vulnerability in the ConnectToHub API method of SmarterTools SmarterMail, allowing unauthenticated remote attackers to redirect the mail server to a malicious HTTP endpoint and execute arbitrary OS commands. Successful exploitation requires no credentials or user interaction and results in full server compromise. CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog with a federal patch deadline of February 26, 2026.