<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/warlock-gang-breaches-smartertools-via-smartermail-bugs-gvnmn6pq9" -->

---
title: Warlock Gang Breaches SmarterTools Via SmarterMail Bugs
description: The Warlock ransomware group breached SmarterTools by exploiting two critical vulnerabilities (CVE-2026-24423 and CVE-2026-23760) in SmarterMail, the company&#x27;s...
canonical: https://daily.dev/posts/warlock-gang-breaches-smartertools-via-smartermail-bugs-gvnmn6pq9
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Warlock Gang Breaches SmarterTools Via SmarterMail Bugs | daily.dev
og:description: The Warlock ransomware group breached SmarterTools by exploiting two critical vulnerabilities (CVE-2026-24423 and CVE-2026-23760) in SmarterMail, the company&#x27;s...
og:url: https://daily.dev/posts/warlock-gang-breaches-smartertools-via-smartermail-bugs-gvnmn6pq9
og:image: https://api.daily.dev/og/posts/GvNMN6Pq9.png
og:image:alt: Warlock Gang Breaches SmarterTools Via SmarterMail Bugs
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Warlock Gang Breaches SmarterTools Via SmarterMail Bugs

**[Dark Reading](https://daily.dev/sources/dr)** · 4 min read · 0 upvotes · 0 comments

## Summary

The Warlock ransomware group breached SmarterTools by exploiting two critical vulnerabilities (CVE-2026-24423 and CVE-2026-23760) in SmarterMail, the company's own mail server product. CVE-2026-24423 is an unauthenticated RCE flaw in the ConnectToHub API, while CVE-2026-23760 is an authentication bypass enabling forced admin password resets — both scoring 9.3 CVSS. The breach occurred on Jan. 29 via a single unpatched server among 30 SmarterMail instances on the company's network. Twelve Windows servers were compromised; Linux servers were unaffected. In response, SmarterTools isolated networks, eliminated Windows infrastructure where possible, dropped Active Directory, and reset all passwords. Some customers were also impacted, as the Warlock Group installs files and waits up to a week before encrypting data. Both vulnerabilities were patched in SmarterMail release 9511 on Jan. 15, and all users are urged to update immediately.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.darkreading.com/application-security/warlock-gang-breaches-smartertools-smartermail-bugs>

## Similar posts on daily.dev

- [SmarterMail Auth Bypass Exploited in the Wild Two Days After Patch Release](https://daily.dev/posts/smartermail-auth-bypass-exploited-in-the-wild-two-days-after-patch-release-pbpnf2bdj) · The Hacker News · 1 upvotes · 0 comments
- [Web Shells, Tunnels, and Ransomware: Dissecting a Warlock Attack](https://daily.dev/posts/web-shells-tunnels-and-ransomware-dissecting-a-warlock-attack-pabj8acyc) · Trend Micro · 0 upvotes · 0 comments

---

Tags: [#vulnerability](https://daily.dev/tags/vulnerability), [#ransomware](https://daily.dev/tags/ransomware), [#appsec](https://daily.dev/tags/appsec)

[View this post on daily.dev](https://daily.dev/posts/warlock-gang-breaches-smartertools-via-smartermail-bugs-gvnmn6pq9)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Warlock Gang Breaches SmarterTools Via SmarterMail Bugs","url":"https://daily.dev/posts/warlock-gang-breaches-smartertools-via-smartermail-bugs-gvnmn6pq9","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/warlock-gang-breaches-smartertools-via-smartermail-bugs-gvnmn6pq9"},"datePublished":"2026-02-23T22:51:32.293Z","dateModified":"2026-02-23T22:52:30.319Z","description":"The Warlock ransomware group breached SmarterTools by exploiting two critical vulnerabilities (CVE-2026-24423 and CVE-2026-23760) in SmarterMail, the company's...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/e12ca1186586196a9dea6e8185d32b53?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/e12ca1186586196a9dea6e8185d32b53?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Dark Reading","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Dark Reading","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/dr","url":"https://daily.dev/sources/dr"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/warlock-gang-breaches-smartertools-via-smartermail-bugs-gvnmn6pq9","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"vulnerability,ransomware,appsec","timeRequired":"PT4M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Dark Reading","item":"https://daily.dev/sources/dr"},{"@type":"ListItem","position":3,"name":"Warlock Gang Breaches SmarterTools Via SmarterMail Bugs"}]}
```

