Dev.to
7/15/2026

Exim CVE-2026-45185 — Unauthenticated RCE in the World's Most Deployed Mail Server
Short summary
CVE-2026-45185 is a critical unauthenticated remote code execution vulnerability in Exim 4.97–4.99.2 when built with GnuTLS, affecting the default MTA on Debian, Ubuntu, and other major Linux distributions. The use-after-free flaw in BDAT parsing was discovered by XBOW using AI assistance, marking the second confirmed case of AI-assisted zero-day development in a single week. Organizations should upgrade to Exim 4.99.3 immediately, verify their TLS build, and restrict SMTP access as a temporary mitigation.
- •CVE-2026-45185: unauthenticated RCE in Exim 4.97–4.99.2 with GnuTLS via BDAT use-after-free
- •Exploit developed with AI assistance by XBOW — second AI-assisted zero-day in one week
- •Patch to Exim 4.99.3 immediately; OpenSSL builds not affected by this specific flaw
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



