Back to feed
Dev.to
Dev.to
7/15/2026
Exim CVE-2026-45185 — Unauthenticated RCE in the World's Most Deployed Mail Server

Exim CVE-2026-45185 — Unauthenticated RCE in the World's Most Deployed Mail Server

Short summary

CVE-2026-45185 is a critical unauthenticated remote code execution vulnerability in Exim 4.97–4.99.2 when built with GnuTLS, affecting the default MTA on Debian, Ubuntu, and other major Linux distributions. The use-after-free flaw in BDAT parsing was discovered by XBOW using AI assistance, marking the second confirmed case of AI-assisted zero-day development in a single week. Organizations should upgrade to Exim 4.99.3 immediately, verify their TLS build, and restrict SMTP access as a temporary mitigation.

  • CVE-2026-45185: unauthenticated RCE in Exim 4.97–4.99.2 with GnuTLS via BDAT use-after-free
  • Exploit developed with AI assistance by XBOW — second AI-assisted zero-day in one week
  • Patch to Exim 4.99.3 immediately; OpenSSL builds not affected by this specific flaw

Generated with AI, which can make mistakes.

Is this a good recommendation for you?

Comments

Failed to load comments. Please try again.

Explore more