logo

New Critical Exim Mailer Allows Remote Attacker to Execute Arbitrary Code

ID: 4be90c6d-444f-5671-94b2-27a787cd9cbe

STIX ID: report--4be90c6d-444f-5671-94b2-27a787cd9cbe

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-05-14

Date Updated: 2026-05-22

Author: Abinaya

...
...

Dead.Letter (CVE-2026-45185) is a critical unauthenticated remote code execution vulnerability in Exim 4.97–4.99.2 when compiled with GnuTLS; attackers can trigger a one-byte heap corruption by sending a TLS close notification followed by a final cleartext byte during an SMTP transfer, enabling full server compromise. The flaw carries a CVSS of 9.8, primarily affects Debian/Ubuntu-derived packages that use GnuTLS, and is mitigated only by upgrading to Exim 4.99.3.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.