« All posts

Exim CVE-2026-45185 — Unauthenticated RCE in the World's Most Deployed Mail Server

CVE-2026-45185 exposes Exim to unauthenticated remote code execution. Upgrade to version 4.99.3 to secure affected systems.

CVE-2026-45185 is a use-after-free vulnerability in Exim's BDAT message body parsing, enabling unauthenticated remote code execution. Affects Exim versions 4.97 to 4.99.2 built with GnuTLS. Immediate upgrade to version 4.99.3 is necessary to mitigate this risk.

This synthesis was produced from its source by AI; there is no human editor or manual review step. How we work