logo

New Exim Vulnerability Enables Arbitrary Code Execution Attacks

ID: 503c9842-21d5-5296-9f05-fdfd27e30f18

STIX ID: report--503c9842-21d5-5296-9f05-fdfd27e30f18

Feed Name: Cyber Press

Threat Score
90/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

Author: AnuPriya

...
...

A critical Exim vulnerability (CVE-2026-45185, “Dead.Letter”) in Exim 4.97–4.99.2 compiled with GnuTLS and using STARTTLS+BDAT permits unauthenticated remote code execution via a use‑after‑free triggered by TLS shutdown during BDAT processing; researchers demonstrated reliable escalation from a one‑byte write to full RCE. Exim 4.99.3 fixes the root cause; mitigations include switching to OpenSSL, disabling BDAT, or restricting STARTTLS, and administrators are strongly urged to patch immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.