CVE-2026-26930: XSS
Published Feb 16, 2026
·Updated
SmarterTools SmarterMail before 9526 allows XSS via MAPI requests.
Affected Software
1 affected component
SmarterTools SmarterMail<9526
Event History
Feb 16, 2026
CVE Published
via MITRE·04:27 PM
Data Sourced
via MITRE·04:27 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:18 PM
DescriptionSeverityWeakness
Feb 9, 58115
Event
via FIRST·06:21 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-26930?
CVE-2026-26930 is classified as a Medium severity vulnerability due to its potential to allow XSS attacks.
2
How do I fix CVE-2026-26930?
To fix CVE-2026-26930, upgrade to SmarterMail version 9526 or later.
3
What type of vulnerability is CVE-2026-26930?
CVE-2026-26930 is an XSS (Cross-Site Scripting) vulnerability affecting SmarterTools SmarterMail.
4
Can I be affected by CVE-2026-26930 if I am using SmarterMail version 9526 or later?
No, if you are using SmarterMail version 9526 or later, you are not affected by CVE-2026-26930.
5
What are the potential impacts of CVE-2026-26930?
The potential impacts of CVE-2026-26930 include unauthorized script execution in a user's browser, leading to data theft or session hijacking.