logo

Critical Exim bug bypasses security filters on 1.5 million mail servers

ID: a0f0c9af-4c90-5e60-a26c-15ffdee259f3

STIX ID: report--a0f0c9af-4c90-5e60-a26c-15ffdee259f3

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2024-07-12

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

CVE-2024-39929 is a critical Exim MTA vulnerability (affecting releases up to 4.97.1) that permits attackers to bypass the mime_filename extension-blocking mechanism and deliver executable attachments into user mailboxes; Exim released a patch on July 10, 2024, Censys observed ~1.57M potentially vulnerable public servers, and a PoC is available though no active exploitation is reported — administrators should patch or restrict remote access to affected servers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.