{"id":745,"date":"2026-06-22T17:12:51","date_gmt":"2026-06-22T11:42:51","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=745"},"modified":"2026-08-18T17:13:31","modified_gmt":"2026-08-18T11:43:31","slug":"gravity-smtp-vulnerability-exploitation-raises-email-credential-exposure-risks","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/gravity-smtp-vulnerability-exploitation-raises-email-credential-exposure-risks\/","title":{"rendered":"Gravity SMTP Vulnerability Exploitation Raises Email Credential Exposure Risks"},"content":{"rendered":"<p>The Gravity SMTP vulnerability is drawing increased attention after researchers reported active exploitation targeting vulnerable WordPress sites. The flaw, tracked as CVE-2026-4020, affects Gravity SMTP versions 2.1.4 and earlier and allows unauthenticated users to retrieve sensitive configuration data through an exposed REST API endpoint.<\/p>\n<p>What makes this incident notable is not just the vulnerability itself but the type of data exposed. Wordfence reported that unauthenticated attackers could retrieve API keys, secrets, OAuth tokens, and configuration details associated with connected email services. The plugin is installed on approximately 100,000 WordPress sites, increasing the potential exposure footprint.<\/p>\n<p>Recent reporting indicates that attackers are using large-scale automated activity to target the vulnerability, with Wordfence blocking more than <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/hackers-exploit-info-disclosure-bug-in-gravity-smtp-wordpress-plugin\/utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=gravity_smtp_vulnerability\" target=\"_blank\" rel=\"noopener\">17 million<\/a> exploit attempts against protected customers.<\/p>\n<h2>Why Security Teams Are Paying Attention<\/h2>\n<p>Many information-disclosure vulnerabilities remain low-priority patching items. This case is different because the exposed information may include credentials used to authenticate with third-party email services.<\/p>\n<p>Wordfence reported active exploitation of the flaw and said it blocked more than 17 million exploit attempts against protected sites.<\/p>\n<p>Three factors make the vulnerability notable:<\/p>\n<ul>\n<li>No authentication is required to access the exposed endpoint.<\/li>\n<li>The disclosed data may include API keys, OAuth tokens, and email-service credentials.<\/li>\n<li>The exposed report can also provide insight into the site&#8217;s technology stack.<\/li>\n<\/ul>\n<p>The combination of active exploitation and potential credential exposure elevates the risk beyond a typical configuration disclosure issue.<\/p>\n<h2>How the Vulnerability Exposes Sensitive Data<\/h2>\n<p>The flaw originates from a REST API endpoint located at:<\/p>\n<p><code>\/wp-json\/gravitysmtp\/v1\/tests\/mock-data<\/code><\/p>\n<p>According to researchers, the endpoint\u2019s permission_callback function always returns true. As a result, unauthenticated requests can retrieve JSON system-report data from the plugin.<\/p>\n<p>The report may contain:<\/p>\n<ul>\n<li>API keys and secrets<\/li>\n<li>OAuth tokens<\/li>\n<li>Email-service credentials<\/li>\n<li>WordPress configuration details<\/li>\n<li>Active plugin inventories<\/li>\n<li>Theme information<\/li>\n<li>PHP and server environment details<\/li>\n<li>Database configuration information<\/li>\n<\/ul>\n<h2>What Makes the Exposed Data Valuable to Attackers<\/h2>\n<p>The incident goes beyond a typical WordPress plugin exploit, as the exposed information can enable both credential abuse and reconnaissance.<\/p>\n<table>\n<thead>\n<tr>\n<th>Exposed Data<\/th>\n<th>Potential Security Impact<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Email-service credentials<\/td>\n<td>Potential unauthorized email delivery through trusted infrastructure<\/td>\n<\/tr>\n<tr>\n<td>OAuth tokens<\/td>\n<td>Potential access to connected email-service integrations<\/td>\n<\/tr>\n<tr>\n<td>API keys<\/td>\n<td>Abuse of configured email integrations<\/td>\n<\/tr>\n<tr>\n<td>Plugin inventory<\/td>\n<td>Identification of additional attack opportunities<\/td>\n<\/tr>\n<tr>\n<td>Server details<\/td>\n<td>Faster environment profiling<\/td>\n<\/tr>\n<tr>\n<td>Database information<\/td>\n<td>Improved reconnaissance for follow-on attacks<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Wordfence warned that exposed credentials may allow attackers to abuse legitimate email services configured within the plugin if those credentials remain active.<\/p>\n<p>This risk is particularly significant because organizations often trust emails sent through legitimate providers and established domains. If exposed credentials remain valid, attackers may be able to use trusted email infrastructure rather than relying on newly created or suspicious domains.<\/p>\n<h2>The Challenge Doesn&#8217;t End with Patching<\/h2>\n<p>Upgrading to Gravity SMTP 2.1.5 removes the vulnerable endpoint, but it does not invalidate credentials that may have been exposed before remediation.<\/p>\n<p>Organizations that used affected versions should evaluate whether:<\/p>\n<ul>\n<li>API keys were configured in Gravity SMTP.<\/li>\n<li>OAuth tokens were stored in the plugin.<\/li>\n<li>Email-service credentials remain active.<\/li>\n<li>Logs show requests to the vulnerable endpoint.<\/li>\n<li>Mail-provider accounts have generated unusual activity.<\/li>\n<\/ul>\n<p>The vulnerability highlights a common challenge with information disclosure flaws. Once sensitive credentials have been exposed, patching addresses future exploitation, but does not eliminate the risk associated with previously disclosed secrets.<\/p>\n<p>Wordfence recommends rotating exposed credentials and reviewing connected email-service accounts for signs of misuse.<\/p>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/8-security-blind-spots-putting-your-business-at-risk.jpg?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>8 Security Blind Spots Putting Your Business at Risk<\/h4><p>Common security blind spots that expose organizations to cyber threats.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/security-blind-spots\/\" aria-label=\"8 Security Blind Spots Putting Your Business at Risk\"><\/a><\/div><\/div><\/div>\n<h2>Assessing Potential Exposure<\/h2>\n<p>Updating the plugin addresses the vulnerable endpoint, but it does not invalidate credentials that attackers may have already exposed. Wordfence recommends treating potential credential exposure as a separate response activity, even after you update the vulnerable plugin.<\/p>\n<p>Security teams should review the following:<\/p>\n<ul>\n<li>Was Gravity SMTP running version 2.1.4 or earlier?<\/li>\n<li>Was the vulnerable endpoint accessible before remediation?<\/li>\n<li>Were any API keys or OAuth tokens configured in the plugin?<\/li>\n<li>Have those credentials been rotated?<\/li>\n<li>Do web logs contain requests to the vulnerable endpoint?<\/li>\n<li>Has outbound email activity changed unexpectedly?<\/li>\n<\/ul>\n<p>A key <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-are-indicators-of-compromise-iocs-in-edr\/\">indicator of compromise<\/a> is access to the <code>\/wp-json\/gravitysmtp\/v1\/tests\/mock-data<\/code> endpoint, particularly when accompanied by the <code>?page=gravitysmtp-settings<\/code> parameter.<\/p>\n<h2>Defensive Actions That Deserve Immediate Attention<\/h2>\n<p>Organizations using affected versions should prioritize:<\/p>\n<ul>\n<li>Upgrading to Gravity SMTP 2.1.5 or later.<\/li>\n<li>Rotating exposed credentials and secrets.<\/li>\n<li>Revoking and reissuing OAuth tokens where applicable.<\/li>\n<li>Reviewing email-provider activity logs.<\/li>\n<li>Investigating requests to the vulnerable REST endpoint.<\/li>\n<li>Monitoring for unusual outbound email activity.<\/li>\n<li>Reviewing administrator account activity associated with email-service management.<\/li>\n<\/ul>\n<p>Wordfence recommends credential rotation in addition to patching because previously exposed credentials may remain valid after the software update.<\/p>\n<h2>How Hexnode Supports Investigation and Response<\/h2>\n<p>The Gravity SMTP vulnerability highlights the importance of responding quickly to credential exposure events and maintaining visibility into administrative systems involved in remediation efforts.<\/p>\n<p><a href=\"https:\/\/www.hexnode.com\/\">Hexnode<\/a> helps organizations manage and monitor enrolled devices, enforce compliance policies, and support device update management across their endpoint fleet.<\/p>\n<p>Hexnode provides device management, compliance enforcement, and endpoint administration capabilities that can support operational security and device management workflows.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-framework.png?format=webp\" class=\"resource-box__image\" alt=\"cybersecurity framework\" loading=\"lazy\" srcset=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-framework.png?format=webp 960w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-framework-300x225.png?format=webp 300w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-framework-768x576.png?format=webp 768w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-framework-133x100.png?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"cybersecurity framework\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Building a cybersecurity framework for your enterprise\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Explore cybersecurity frameworks and how UEM strengthens security, compliance, visibility, and risk management.\r\n\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/white-papers\/building-a-cybersecurity-framework-for-your-enterprise\/'>\n                            DOWNLOAD\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h2>Conclusion<\/h2>\n<p>The Gravity SMTP vulnerability demonstrates how an information disclosure flaw can evolve into a broader identity and email security concern. Active exploitation and the potential exposure of credentials and system configuration data increase the potential impact beyond the original vulnerability.<\/p>\n<p>Organizations should focus not only on patching systems but also on determining whether an attack exposed credentials before remediation. Reviewing administrative activity, monitoring email-service accounts, and rotating potentially exposed credentials remain important steps in reducing the risk of follow-on misuse.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Investigate credential exposure with greater visibility <\/h5><p>See how Hexnode helps security teams monitor endpoints and support incident response workflows. <\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> SIGN UP NOW<\/a><\/div><\/div>\n<div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><h2 class=\"faq-main-title\">FAQs<\/h2><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">What versions of Gravity SMTP are affected?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>CVE-2026-4020 affects Gravity SMTP versions 2.1.4 and earlier. Version 2.1.5 addresses this vulnerability.<\/p>\n<\/div><\/div><\/div> <div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">What information can attackers access through the vulnerable endpoint?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>The exposed system report may contain API keys, secrets, OAuth tokens, email-service credentials, WordPress configuration data, plugin and theme information, and server environment details.<\/p>\n<\/div><\/div><\/div> <div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">What should organizations do if they were running a vulnerable version?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Organizations should update to Gravity SMTP 2.1.5 or later, review logs for requests to the vulnerable endpoint, and evaluate whether exposed credentials or tokens require rotation.<\/p>\n<\/div><\/div><\/div><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>The Gravity SMTP vulnerability is drawing increased attention after researchers reported active exploitation targeting vulnerable&#8230;<\/p>\n","protected":false},"author":5,"featured_media":749,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[13,14],"class_list":["post-745","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-identity-abuse","category-supply-chain-attack","product_category-identity-provider","tab_group-vulnerabilities"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Gravity SMTP Vulnerability Exposes Email Credentials<\/title>\n<meta name=\"description\" content=\"The Gravity SMTP vulnerability is under active exploitation, exposing API keys, OAuth tokens, and email credentials on WordPress sites.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/gravity-smtp-vulnerability-exploitation-raises-email-credential-exposure-risks\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Gravity SMTP Vulnerability Exposes Email Credentials\" \/>\n<meta property=\"og:description\" content=\"The Gravity SMTP vulnerability is under active exploitation, exposing API keys, OAuth tokens, and email credentials on WordPress sites.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/gravity-smtp-vulnerability-exploitation-raises-email-credential-exposure-risks\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-06-22T11:42:51+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-18T11:43:31+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/gravity-smtp-vulnerability.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Sophia Hart\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sophia Hart\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/gravity-smtp-vulnerability-exploitation-raises-email-credential-exposure-risks\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/gravity-smtp-vulnerability-exploitation-raises-email-credential-exposure-risks\\\/\"},\"author\":{\"name\":\"Sophia Hart\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\"},\"headline\":\"Gravity SMTP Vulnerability Exploitation Raises Email Credential Exposure Risks\",\"datePublished\":\"2026-06-22T11:42:51+00:00\",\"dateModified\":\"2026-08-18T11:43:31+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/gravity-smtp-vulnerability-exploitation-raises-email-credential-exposure-risks\\\/\"},\"wordCount\":1021,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/gravity-smtp-vulnerability-exploitation-raises-email-credential-exposure-risks\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/gravity-smtp-vulnerability.jpeg?format=webp\",\"articleSection\":[\"Identity Abuse\",\"Supply Chain Attack\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/gravity-smtp-vulnerability-exploitation-raises-email-credential-exposure-risks\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/gravity-smtp-vulnerability-exploitation-raises-email-credential-exposure-risks\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/gravity-smtp-vulnerability-exploitation-raises-email-credential-exposure-risks\\\/\",\"name\":\"Gravity SMTP Vulnerability Exposes Email Credentials\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/gravity-smtp-vulnerability-exploitation-raises-email-credential-exposure-risks\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/gravity-smtp-vulnerability-exploitation-raises-email-credential-exposure-risks\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/gravity-smtp-vulnerability.jpeg?format=webp\",\"datePublished\":\"2026-06-22T11:42:51+00:00\",\"dateModified\":\"2026-08-18T11:43:31+00:00\",\"description\":\"The Gravity SMTP vulnerability is under active exploitation, exposing API keys, OAuth tokens, and email credentials on WordPress sites.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/gravity-smtp-vulnerability-exploitation-raises-email-credential-exposure-risks\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/gravity-smtp-vulnerability-exploitation-raises-email-credential-exposure-risks\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/gravity-smtp-vulnerability-exploitation-raises-email-credential-exposure-risks\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/gravity-smtp-vulnerability.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/gravity-smtp-vulnerability.jpeg?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"gravity smtp vulnerability\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/gravity-smtp-vulnerability-exploitation-raises-email-credential-exposure-risks\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Gravity SMTP Vulnerability Exploitation Raises Email Credential Exposure Risks\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\",\"name\":\"Sophia Hart\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"caption\":\"Sophia Hart\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/sophia-hart\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Gravity SMTP Vulnerability Exposes Email Credentials","description":"The Gravity SMTP vulnerability is under active exploitation, exposing API keys, OAuth tokens, and email credentials on WordPress sites.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/gravity-smtp-vulnerability-exploitation-raises-email-credential-exposure-risks\/","og_locale":"en_US","og_type":"article","og_title":"Gravity SMTP Vulnerability Exposes Email Credentials","og_description":"The Gravity SMTP vulnerability is under active exploitation, exposing API keys, OAuth tokens, and email credentials on WordPress sites.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/gravity-smtp-vulnerability-exploitation-raises-email-credential-exposure-risks\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-06-22T11:42:51+00:00","article_modified_time":"2026-08-18T11:43:31+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/gravity-smtp-vulnerability.jpeg?format=webp","type":"image\/jpeg"}],"author":"Sophia Hart","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Sophia Hart","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/gravity-smtp-vulnerability-exploitation-raises-email-credential-exposure-risks\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/gravity-smtp-vulnerability-exploitation-raises-email-credential-exposure-risks\/"},"author":{"name":"Sophia Hart","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430"},"headline":"Gravity SMTP Vulnerability Exploitation Raises Email Credential Exposure Risks","datePublished":"2026-06-22T11:42:51+00:00","dateModified":"2026-08-18T11:43:31+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/gravity-smtp-vulnerability-exploitation-raises-email-credential-exposure-risks\/"},"wordCount":1021,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/gravity-smtp-vulnerability-exploitation-raises-email-credential-exposure-risks\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/gravity-smtp-vulnerability.jpeg?format=webp","articleSection":["Identity Abuse","Supply Chain Attack"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/gravity-smtp-vulnerability-exploitation-raises-email-credential-exposure-risks\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/gravity-smtp-vulnerability-exploitation-raises-email-credential-exposure-risks\/","url":"https:\/\/www.hexnode.com\/threat-watch\/gravity-smtp-vulnerability-exploitation-raises-email-credential-exposure-risks\/","name":"Gravity SMTP Vulnerability Exposes Email Credentials","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/gravity-smtp-vulnerability-exploitation-raises-email-credential-exposure-risks\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/gravity-smtp-vulnerability-exploitation-raises-email-credential-exposure-risks\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/gravity-smtp-vulnerability.jpeg?format=webp","datePublished":"2026-06-22T11:42:51+00:00","dateModified":"2026-08-18T11:43:31+00:00","description":"The Gravity SMTP vulnerability is under active exploitation, exposing API keys, OAuth tokens, and email credentials on WordPress sites.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/gravity-smtp-vulnerability-exploitation-raises-email-credential-exposure-risks\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/gravity-smtp-vulnerability-exploitation-raises-email-credential-exposure-risks\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/gravity-smtp-vulnerability-exploitation-raises-email-credential-exposure-risks\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/gravity-smtp-vulnerability.jpeg?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/gravity-smtp-vulnerability.jpeg?format=webp","width":1340,"height":700,"caption":"gravity smtp vulnerability"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/gravity-smtp-vulnerability-exploitation-raises-email-credential-exposure-risks\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"Gravity SMTP Vulnerability Exploitation Raises Email Credential Exposure Risks"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430","name":"Sophia Hart","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","caption":"Sophia Hart"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/sophia-hart\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/745","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=745"}],"version-history":[{"count":2,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/745\/revisions"}],"predecessor-version":[{"id":752,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/745\/revisions\/752"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/749"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=745"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=745"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}