The Warlock ransomware group breached SmarterTools by exploiting two critical vulnerabilities (CVE-2026-24423 and CVE-2026-23760) in SmarterMail, the company's own mail server product. CVE-2026-24423 is an unauthenticated RCE flaw in the ConnectToHub API, while CVE-2026-23760 is an authentication bypass enabling forced admin

4m read time From darkreading.com
Post cover image
Table of contents
Fallout of the SmarterTools BreachThreat Actors Target SmarterMail Customers

Sort: