SmarterMail auth bypass flaw now exploited to hijack admin accounts

Published on January 22, 2026

Hackers began exploiting an authentication bypass vulnerability in SmarterTools' SmarterMail email server and collaboration tool that allows resetting admin passwords. [...]