Singapore’s Cyber Security Agency (CSA) has released an urgent alert warning organizations about a critical vulnerability in SmarterTools’ SmarterMail email server software, tracked as CVE-2025-52691. Rated with a maximum CVSS score of 10.0, the flaw enables unauthenticated remote code execution through arbitrary file uploads. Due to the ease of exploitation and the potential for full system compromise, CSA has urged affected organizations to take immediate remediation steps. The vulnerability stems from improper handling of file uploads within SmarterMail, an enterprise-grade email and collaboration platform. Exploiting this weakness, attackers can upload specially crafted files without authentication and write them to arbitrary directories on the server. If the environment processes executable file types automatically—such as scripts or web shells—the uploaded files may be executed as code, granting attackers control with the same privileges as the SmarterMail service. This significantly increases the risk of server takeover, data exposure, and lateral movement within enterprise networks. According to CSA, SmarterMail builds 9406 and earlier are affected. The issue was addressed in Build 9413, with subsequent security enhancements included in later releases. Organizations are strongly advised to upgrade to Build 9483 or later to ensure full protection. While there are currently no confirmed reports of active exploitation, the combination of unauthenticated access and remote code execution capability makes this vulnerability a high-priority threat that should be addressed without delay.
Security researchers have identified a new variant of the SparkCat malware circulating on both the Apple App Store and Google Play Store, more than a year after its initial discove...
The European Union’s cybersecurity agency, CERT-EU, has attributed a significant cloud breach involving the European Commission to the TeamPCP threat group. The attack targeted t...
Microsoft has rolled out automatic updates for unmanaged Windows 11 24H2 Home and Pro edition devices to Windows 11 25H2, also known as the Windows 11 2025 Update. This transition ...