peter bassill · operator
$ cve CVE-2025-52691 JSON

CVE-2025-52691 KEV

10.0
CRITICAL · CVSS 3.1 · EPSS 85.7% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2026-02-16.

Description

Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS85.66% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-434
On CISA KEVyes — remediate by 2026-02-16
Public exploitnone known
Published2025-12-29
Last modified2026-06-17

CISA KEV

NameSmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability
Added2026-01-26
Due2026-02-16
Vendor / productSmarterTools / SmarterMail
Ransomware useknown

Affected (1)

VendorProduct
smartertoolssmartermail

References

→ the Explorer  ·  watch your stack  ·  NVD