Threat Intelligence / CVE / CVE-2025-52691
CVE-2025-52691
CISA KEVSuccessful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.
CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Weaknesses (CWE)
CWE-434
Threats tracking this CVE
References
- https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2025-124/
- https://github.com/watchtowrlabs/watchTowr-vs-SmarterMail-CVE-2025-52691?ref=labs.watchtowr.com
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-52691
Full detection coverage & IOCs for threats exploiting CVE-2025-52691 are available via the Threadlinqs MCP server (Purple tier). View plans →