Exim Directory Traversal Vulnerability Exposes Files Outside the Mail Spool
ID: 335405b4-70cf-56e1-8a96-a5e8bad69099
STIX ID: report--335405b4-70cf-56e1-8a96-a5e8bad69099
Feed Name: Cyber Press
Threat Score
A high-severity Exim directory traversal vulnerability (EXIM-Security-2026-06-22.1 / GCVE-25-2026-07-45-1) allows local users with shell access to manipulate queue-name arguments to read files outside the mail spool and potentially escalate privileges; it affects Exim 4.88 through 4.99.4 and master, and is fixed in Exim 4.99.5 — organizations, especially multi-tenant and shared-hosting environments, should upgrade immediately and audit for untrusted local access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
