New Critical Exim Mailer Allows Remote Attacker to Execute Arbitrary Code
ID: 4be90c6d-444f-5671-94b2-27a787cd9cbe
STIX ID: report--4be90c6d-444f-5671-94b2-27a787cd9cbe
Feed Name: cybersecurityNews.com
Threat Score
Dead.Letter (CVE-2026-45185) is a critical unauthenticated remote code execution vulnerability in Exim 4.97–4.99.2 when compiled with GnuTLS; attackers can trigger a one-byte heap corruption by sending a TLS close notification followed by a final cleartext byte during an SMTP transfer, enabling full server compromise. The flaw carries a CVSS of 9.8, primarily affects Debian/Ubuntu-derived packages that use GnuTLS, and is mitigated only by upgrading to Exim 4.99.3.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
