Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.2
SmarterMail allows attackers to inject malicious scripts via email
CVE-2026-26930
Summary
SmarterMail's email software has a security flaw that lets attackers inject malicious code into emails. This could allow them to take control of your email account or steal sensitive information. Update to the latest version to fix this issue.
Original title
SmarterTools SmarterMail before 9526 allows XSS via MAPI requests.
Original description
SmarterTools SmarterMail before 9526 allows XSS via MAPI requests.
nvd CVSS3.1
7.2
Vulnerability type
CWE-79
Cross-site Scripting (XSS)
Published: 16 Feb 2026 · Updated: 11 Mar 2026 · First seen: 6 Mar 2026