CVE-2026-24423
Exploited in the Wild
✓ Confirmed 0-Day
Triaged: March 5, 2026
5 articles
EPSS Score
Source: FIRST.org · 2026-05-24
82.03%
probability
This CVE has a 82.03% probability
of being exploited in the next 30 days.
0%
Top 99.2th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Attack Intelligence
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA-Advisories
Feb 05, 2026
⚡ Weekly Recap: Proxy Botnet, Office Zero-Day, MongoDB Ransoms, AI Hijacks & New Threats
TheHackerNews
Feb 02, 2026
Warlock Ransomware Breaches SmarterTools Through Unpatched SmarterMail Server
TheHackerNews
Feb 10, 2026
SmarterMail Fixes Critical Unauthenticated RCE Flaw with CVSS 9.3 Score
TheHackerNews
Jan 30, 2026
Telegram channels expose rapid weaponization of SmarterMail flaws
BleepingComputer
Feb 18, 2026
Signal Intelligence
Confidence
85%
EPSS
82.03%
Mentions
5
Last Seen
Feb 18, 2026
CNA Information
Analyst Note
CVE-2026-24423 is a critical SmarterMail RCE vulnerability (CVSS 9.3) explicitly documented as exploited in the wild by Warlock ransomware on January 29, 2026, prior to patch availability. CISA added it to the KEV catalog for known exploited vulnerabilities, and multiple sources confirm active exploitation and weaponization.
Threat Actors 4
APT 28
apt_group
Information theft and espionage
🇷🇺 RU
TAG-28
apt_group
Information theft and espionage
🇨🇳 CN
Roaming Tiger
apt_group
Information theft and espionage
🇨🇳 CN
White Bear
apt_group
Information theft and espionage
🇷🇺 RU
Triage Info
Decided atMar 05, 2026