logo

Exim BDAT Vulnerability Exposes Email Servers to Remote Attacks

ID: dba719a8-b9e1-5880-92bd-4cc8dbc6ea1d

STIX ID: report--dba719a8-b9e1-5880-92bd-4cc8dbc6ea1d

Feed Name: The Cyber Express

Threat Score
75/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

Author: Ashish Khaitan

...
...

**Executive Summary:** CVE-2026-45185 (aka "Dead.Letter") is a critical remote use-after-free vulnerability in Exim's BDAT (SMTP CHUNKING) processing when Exim is compiled with GnuTLS; a TLS close_notify during an active BDAT transfer followed by additional cleartext data can cause memory corruption and potentially lead to code execution. The flaw affects Exim 4.97 through 4.99.2 (GnuTLS builds) and is resolved in Exim 4.99.3; administrators are advised to upgrade immediately as no other mitigations are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.