New critical Exim mailer flaw allows remote code execution
ID: b5f9fa24-64fd-5034-80b3-4d7ad5d07d50
STIX ID: report--b5f9fa24-64fd-5034-80b3-4d7ad5d07d50
Feed Name: Bleeping Computer
Threat Score
A critical unauthenticated remote code execution vulnerability (CVE-2026-45185) was discovered in Exim versions 4.97–4.99.2 built with GnuTLS when STARTTLS and CHUNKING are advertised; the flaw is a user-after-free during TLS shutdown handling of BDAT chunked SMTP. XBOW produced AI-assisted proof-of-concept exploits, and maintainers released a patch in Exim 4.99.3; administrators on affected Debian/Ubuntu and other Linux systems should update immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
