Attackers have increasingly targeted the SmarterMail authentication bypass flaw CVE-2026-23760, a critical vulnerability with a CVSS v4 score of 9.3 that can let unauthenticated users gain administrator privileges. The issue was disclosed on January 22, and MBSD-SOC reported first seeing exploitation attempts on January 30, with activity continuing intermittently before rising sharply after April 23. Public proof-of-concept code is available, increasing the risk of opportunistic exploitation.
Observed attacks attempted to reset administrator credentials by sending a POST request to the /api/v1/auth/force-reset-password endpoint with the IsSysAdmin=true parameter, effectively seeking to take over the admin account. MBSD-SOC said many attack sources were geolocated to Japan. SmarterMail builds earlier than 9511 are affected, and organizations running exposed instances have been urged to update to the latest release and review systems for signs of unauthorized password resets or administrator account compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
MBSD-SOC reported increased attacks during May 2026 targeting SmarterMail CVE-2026-23760. It advised organizations running affected builds earlier than 9511 to update to the latest version, noting that proof-of-concept code was already public.
After intermittent activity following the initial sightings, MBSD-SOC observed an increase in attacks targeting the SmarterMail flaw after April 23, 2026. The report also noted that many observed attack sources were geolocated to Japan.
MBSD-SOC reported first seeing attacks targeting CVE-2026-23760 on January 30, 2026. The observed pattern included a POST request to /api/v1/auth/force-reset-password using IsSysAdmin=true to try to reset the admin account password.
The SmarterMail authentication bypass vulnerability CVE-2026-23760 was publicly disclosed. Successful exploitation can let an attacker bypass authentication and obtain administrator privileges.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.