Story perspectives
Critical Flaw in SmarterMail Software Exposes Systems to Attacks
12/31/2025
1 of 1
Story summary
- The Cyber Security Agency of Singapore warned of CVE-2025-52691 in SmarterTools' SmarterMail software, CVSS 10.0.
- The flaw allows unauthenticated attackers to upload arbitrary files, enabling remote code execution.
- SmarterMail Build 9406 and earlier are affected.
- Build 9413 fixes the vulnerability as of October 9, 2025, with Build 9483 released on December 18, 2025.
- CSA credited Chua Meng Han from the Centre for Strategic Infocomm Technologies for discovering the vulnerability.
