Some are empty, some have some
asp.net code in it to act as a remote shell.
The E-Mail from ST sent last Friday:
Valued Customers,
We wanted to reach out to all customers regarding a vulnerability that was found in SmarterMail and provide a timeline of events.
- On October 2nd, we were notified that a vulnerability was found in a specific version of SmarterMail.
- On October 9th, we released Build 9413, which addressed the issue and has a release note for a “Critical Security Fix”. This is how we have notified customers of critical issues in the past.
- On December 29th, a CVE (Common Vulnerabilities and Exposures) was released publicly, which was related to the issue that was reported to us on October 2nd and fixed on October 9th.
-
- On January 3rd, we notified all customers who hadn't already upgraded that they should install Build 9413, which contained the fix for the CVE.
This particular email is to notify all customers of the timeline of events and announce Build 9504, released today (Jan 8, 2026), and to outline some changes we will be making in our communications moving forward.
Build 9504 (Jan 8, 2026) further strengthens SmarterMail’s overall security. It builds upon the initial fix and provides administrators with additional features and functionality relating to uploads throughout SmarterMail. We strongly encourage all SmarterMail customers to upgrade to this latest release to ensure they are running the most secure and stable Build available.
As a general practice, security-related fixes are announced through our Release Notes, which are published alongside each public Build that we release. These notes are intentionally high-level and do not include specific technical details, as disclosing such information could increase the risk of exploitation for customers who have not yet upgraded. That said, recent discussion within our Community regarding this CVE has been both constructive and valuable. Based on this feedback, we are refining how we communicate about security matters moving forward.
For any future CVEs, we will proactively notify all customers directly rather than relying solely on Release Notes. These notifications will continue to avoid sensitive details in order to protect customer installations. We will also provide follow-up communications to keep customers informed of our progress and will issue a final notification once a fix is available for download.
Over our 23-year history, SmarterMail has had very few CVEs. In every case, fixes were thoroughly tested, verified, and released extremely quickly.
Thank you for your continued trust in SmarterTools. We remain committed to continuously improving both our company and the products we deliver.
Thank you for using SmarterTools products,
The SmarterTools Team