New SmarterMail auth bypass found by analysing the patch

watchTowr Labs has published further research into vulnerabilities in SmarterTools SmarterMail. The starting point was a critical pre-authentication remote code execution flaw, CVE-2025-52691, rated CVSS 10.0, where unauthenticated file uploads could lead to code execution. The new research, tracked as WT-2026-0001, covers an authentication bypass, CVE-2026-23760, in the same code paths. The work shows how attackers with decompilers can analyse published patches and reconstruct flaws in SmarterMail's authentication and upload logic. It underlines how quickly threat actors can turn public fixes into working exploits against real deployments.

What this means for your organisation

The point reaches beyond one mail server. A published patch is also a description of what was wrong, and that description is read by both sides. For organisations, this means the window between a vendor's fix and your own deployment is when risk is highest, not lowest. If you run your own mail server, it is also exposed to the internet around the clock and holds all of your correspondence.

Berigo recommends

  • Update SmarterMail to the latest version and confirm both the authentication and upload fixes are in place.
  • Set a clear internal deadline, measured in days, for deploying critical security updates on internet-facing systems.
  • Restrict administrative interfaces on the mail server to internal networks or VPN.
  • Review logs for unexpected file uploads and logins in the period following the previous patch.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch