News Why the Gravity SMTP Vulnerability Should Change How You Think About Plugin Credentials by Rebecca Sutton June 21, 2026 by Rebecca Sutton June 21, 2026 The Gravity SMTP vulnerability (CVE-2026-4020) is being exploited at mass scale. But the real issue is structural: email plugins holding API keys create a risk that one permission bug can … FacebookTwitterLinkedinEmail