Skip to main content
QUIETLYTIC
Vulnerability

AcyMailing SMTP Newsletter SQL Injection (CVE-2026-57739)

CVE-2026-57739 is a CVSS 9.3 blind SQL injection flaw in the AcyMailing WordPress newsletter plugin, reported exploited by VulnCheck KEV.

CVE-2026-57739
Threat Level
CRITICAL
CVSS
9.3
Status
Active Exploitation
Confidence
Medium
Affected Products
AcyMailing SMTP Newsletter, AcyMailing (through 10.11.0)

CVE-2026-57739 carries a CVSS 3.1 base score of 9.3 against AcyMailing SMTP Newsletter, a WordPress plugin published by AcyMailing Newsletter Team for managing email newsletters and campaigns. NVD classifies it as CWE-89 (SQL Injection), specifically a blind SQL injection, and states the affected range as all versions through 10.11.0. VulnCheck’s KEV feed reports the CVE as exploited, dated August 22, 2026.

That exploitation report is single-sourced. CISA has not added CVE-2026-57739 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion on September 19, 2026. VulnCheck’s catalog admits vendor and researcher exploitation reporting on broader criteria than CISA’s own listing process has accepted; no Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.

What the flaw is

NVD’s own summary states this is a blind SQL injection, meaning the vulnerable query doesn’t return database output directly to the attacker but can still be exploited by observing indirect signals (timing differences or true/false response variations) to extract data one inference at a time. NVD’s summary does not name the specific vulnerable parameter or endpoint; Patchstack’s vulnerability database, cited from NVD’s reference list, tracks the same underlying flaw. The CVSS vector’s Scope-Changed (S:C) component alongside C:H/I:N/A:L indicates the primary impact is confidentiality — consistent with an injection used to read data rather than modify it.

We report NVD’s classification and affected-version boundary as stated. The absence of a named vulnerable parameter is a gap in the publicly available technical detail, not a gap we are filling with speculation.

Evidence and confidence

  • Medium confidence — the CVSS 9.3 score, the vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L), the CWE-89 classification (blind SQL injection specifically), and the affected-version ceiling (10.11.0) all trace to NVD alone. The exploitation report traces to VulnCheck KEV alone.
  • Below-midpoint exploitation probability — FIRST’s EPSS model scores this CVE at 0.004, a 33.8th percentile score as of our ingestion.

No field is in conflict between our two sources. Our data carries no fixed-version field; NVD’s summary states only the affected ceiling.

Why this matters

Newsletter and email-marketing plugins typically hold subscriber lists — names, email addresses, and sometimes segmentation data revealing customer behavior or preferences — making an unauthenticated, no-privileges-required SQL injection in this category a direct path to a subscriber-data breach even though the CVSS vector’s A:L component indicates the injection’s disruptive potential (denial of service) is comparatively limited next to its confidentiality impact. Blind injection techniques can also be slower and quieter than error-based injection, meaning ongoing data extraction against a vulnerable, unpatched site may not produce the kind of obvious error-log signature an operator would notice.

Because NVD’s summary doesn’t specify the vulnerable parameter, site operators should treat the stated version boundary as the operative signal for remediation rather than attempting to identify and block a specific request pattern.

Frequently Asked Questions

What is CVE-2026-57739? A CVSS 9.3 blind SQL injection vulnerability (CWE-89) in the AcyMailing SMTP Newsletter WordPress plugin, affecting all versions through 10.11.0.

Is CVE-2026-57739 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated August 22, 2026. That report is single-sourced; CISA has not listed this CVE as of our September 19, 2026 ingestion, and we have no independent corroboration.

What makes a “blind” SQL injection different? A blind SQL injection doesn’t return database output directly to the attacker; instead, an attacker infers data by observing indirect signals like timing differences or true/false response variations, extracting information more slowly than a direct, error-based injection would allow.

Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.

Which version fixes this? Our data carries no fixed-version field. NVD states versions through 10.11.0 are affected; confirm directly with the vendor’s changelog whether a later release addresses this specific CVE.


Severity, vector, weakness classification, and affected-version ceiling sourced from the National Vulnerability Database record for CVE-2026-57739, which cites Patchstack’s vulnerability database entry. Exploitation status and the August 22, 2026 catalog date are reported by VulnCheck KEV, an authenticated feed with no public per-CVE page to cite. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our ingestion through September 19, 2026. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 VulnCheck KEV

Related intelligence


Analyst tools