logo

Critical Exim Mailer Flaw Enables Remote Code Execution Attacks

ID: 24495d05-3cfb-58d3-88c2-73e261e815a7

STIX ID: report--24495d05-3cfb-58d3-88c2-73e261e815a7

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

Author: Divya

...
...

A critical Exim vulnerability (CVE-2026-45185, "Dead.Letter") in Exim 4.97–4.99.2 built with GnuTLS lets unauthenticated attackers trigger a one-byte write into freed heap memory during mixed BDAT/TLS shutdown, enabling full remote code execution via allocator metadata corruption; public write-ups and both human and LLM-assisted exploit chains exist, and operators are advised to upgrade to 4.99.3 or mitigate by switching to OpenSSL, disabling BDAT, or limiting STARTTLS exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.