CVE Tools

Attackers With Decompilers Strike Again (SmarterTools SmarterMail WT-2026-0001 Auth Bypass)

watchTowr LabsBy Piotr Bazydlo (@chudyPB)9 min read

Reported exploitedSmarterMail
Read at watchTowr Labs

Below is the opening; the full story is at watchTowr Labs.

From watchTowr Labs

Well, well, well - look what we’re back with.

You may recall that merely two weeks ago, we analyzed CVE-2025-52691 - a pre-auth RCE vulnerability in the SmarterTools SmarterMail email solution with a timeline that is typically reserved for KEV hall-of-famers.

The plot of that story had everything;…

Continue at watchTowr Labs

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store