Warlock Ransomware Exploits Unpatched SmarterMail Server at SmarterTools
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
On January 29, 2026, the Warlock ransomware group breached SmarterTools by exploiting an unpatched instance of SmarterMail. The company’s Chief Commercial Officer, Derek Curtis, reported that a mail server, overlooked during updates, was compromised, leading to a breach affecting 12 Windows servers and hosted customers using SmarterTrack. Importantly, the breach did not compromise the company’s website or customer account data.
SmarterTools identified that the attackers gained access and waited several days before escalating their actions, which included taking control of the Active Directory server and deploying ransomware payloads like Velociraptor. This delay allowed the attackers to blend their activities with normal administrative tasks, complicating detection efforts.
Multiple vulnerabilities in SmarterMail were exploited during this incident, including CVE-2025-52691, CVE-2026-23760, and CVE-2026-24423. The latter two vulnerabilities allow for significant unauthorized access, including the ability to reset administrator passwords and execute code remotely.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed that CVE-2026-24423 was being actively exploited in ransomware attacks. Cybersecurity firm ReliaQuest noted that Warlock utilized CVE-2026-23760 to bypass authentication and prepare the ransomware payload on exposed systems.
As a result of this breach, SmarterTools has urged users to upgrade to the latest version of SmarterMail (Build 9526) immediately. This incident underscores the critical importance of maintaining updated software to protect against known vulnerabilities.
Understanding the Risks
This incident illustrates the ongoing threat posed by ransomware groups like Warlock, which exploit unpatched vulnerabilities to gain access to networks. Organizations must remain vigilant about software updates and monitor their systems for unauthorized changes.
Users of SmarterMail should be particularly cautious, as the vulnerabilities exploited in this breach have been confirmed to allow for severe security compromises. Regular updates and monitoring can help mitigate these risks.
Key Takeaways
- Upgrade to the latest version of SmarterMail (Build 9526) immediately to protect against known vulnerabilities.
- Regularly check for and apply updates to all software to prevent exploitation of unpatched vulnerabilities.
- Monitor your network for unauthorized changes or access attempts to detect potential breaches early.
- Isolate mail servers to limit lateral movement within your network in case of a breach.
- Educate employees about the importance of maintaining updated systems and reporting any suspicious activities.
Key Terms & Concepts
- CVE: CVE refers to a list of publicly disclosed cybersecurity vulnerabilities and exposures.
- Ransomware: Ransomware is a type of malicious software that encrypts files and demands payment for their release.
- Active Directory: Active Directory is a directory service developed by Microsoft for Windows domain networks that manages permissions and access to networked resources.
- Velociraptor: Velociraptor is a digital forensics tool used by security professionals to investigate and respond to security incidents.
- Unpatched Vulnerability: An unpatched vulnerability is a security flaw in software that has not been fixed by the vendor, leaving it open to exploitation.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.