CVE-2026-45185Disclosure(exim / exim)

CRITICALCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 25 mentions and remains active

Immediate actions

  • Patch exim exim systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection. This can lead to heap corruption. An unauthenticated network attacker exploiting this vulnerability could execute arbitrary code.

8.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • exim

Threat summary

  • Active exploitation appears in 4 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 89 mentions across 17 observed days

What's happening

  • Active exploitation reported across 4 signals
  • Exploit tool or code specified in 3 signals
  • PoC mentioned or linked in 14 signals
  • Patch or workaround mentioned in 36 signals
  • Technical details provided in 75 signals
  • Disclosure: 38 classified signals
  • Peaked 16d ago at 25 mentions (2026-05-12); latest day: 1
  • 89 total mentions across 17 days

Affected systems

Vendors
Products
exim

Deep dive

Activity timeline89 mentions / 17d
06131925Mentions · 2026-05-12: 25Mentions · 2026-05-13: 23Mentions · 2026-05-14: 14Mentions · 2026-05-15: 4Mentions · 2026-05-16: 3Mentions · 2026-05-17: 5Mentions · 2026-05-18: 1Mentions · 2026-05-19: 1Mentions · 2026-05-20: 1Mentions · 2026-05-22: 1Mentions · 2026-05-23: 2Mentions · 2026-05-31: 1Mentions · 2026-06-07: 2Mentions · 2026-06-12: 1Mentions · 2026-06-13: 1Mentions · 2026-06-22: 3Mentions · 2026-09-11: 1PoC Mentioned / Linked · 2026-05-12: 4PoC Mentioned / Linked · 2026-05-13: 8PoC Mentioned / Linked · 2026-05-14: 1PoC Mentioned / Linked · 2026-05-22: 1Exploit Tool / Code · 2026-05-12: 2Exploit Tool / Code · 2026-05-13: 1Active Exploitation · 2026-05-12: 1Active Exploitation · 2026-05-13: 2Active Exploitation · 2026-05-14: 1Patch / Workaround · 2026-05-12: 9Patch / Workaround · 2026-05-13: 9Patch / Workaround · 2026-05-14: 7Patch / Workaround · 2026-05-15: 3Patch / Workaround · 2026-05-17: 5Patch / Workaround · 2026-05-18: 1Patch / Workaround · 2026-05-19: 1Patch / Workaround · 2026-05-23: 1Technical Details · 2026-05-12: 18Technical Details · 2026-05-13: 21Technical Details · 2026-05-14: 14Technical Details · 2026-05-15: 4Technical Details · 2026-05-16: 1Technical Details · 2026-05-17: 5Technical Details · 2026-05-18: 1Technical Details · 2026-05-19: 1Technical Details · 2026-05-20: 1Technical Details · 2026-05-23: 2Technical Details · 2026-05-31: 1Technical Details · 2026-06-07: 2Technical Details · 2026-06-22: 3Technical Details · 2026-09-11: 105-1205-1305-1405-1505-1605-1705-1805-1905-2005-2205-2305-3106-0706-1206-1306-2209-11
Signal classification5 categories
Disclosure
3842.7%
Patch
2932.6%
PoC
1112.4%
General
89.0%
Active Exploitation
33.4%
Referenced assets48 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-1225
Disclosure10General3Patch8PoC4
2026-05-1323
Active Exploitation2Disclosure9Patch7PoC5
2026-05-1414
Active Exploitation1Disclosure8Patch4PoC1
2026-05-154
Disclosure2Patch2
2026-05-163
Disclosure1General2
2026-05-175
Patch5
2026-05-181
Disclosure1
2026-05-191
Patch1
2026-05-201
Disclosure1
2026-05-221
PoC1
2026-05-232
Disclosure1Patch1
2026-05-311
General1
2026-06-072
Disclosure2
2026-06-121
General1
2026-06-131
General1
2026-06-223
Disclosure2Patch1
2026-09-111
Disclosure1
Full discourse20 posts
  • Brendan Dolan-Gavitt@moyix
    Patch

    Exim 4.99.3 is out, patching CVE-2026-45185, a critical RCE found by XBOW! Check out our post linked in the reply; I'll summarize some details in this thread. https://t.co/F4Dum3xjQ7

    Post summary

    Exim 4.99.3 has released a patch addressing CVE-2026-45185, identified as a critical RCE by XBOW, and the text directs users to a summary of the details.

    575031214733.6K
    33.2K followersView on X
  • H4x0r.DZ 🇰🇵@h4x0r_dz
    Disclosure

    How @Xbow Found an Unauthenticated RCE on Exim https://xbow.com/blog/dead-letter-cve-2026-45185-xbow-found-rce-exim

    Post summary

    Exim CVE-2026-45185 is newly disclosed with an unauthenticated RCE discovered by @Xbow; a blog post likely contains the PoC and technical details.

    0150111687.7K
    81.6K followersView on X
  • The Hacker News@TheHackersNews
    Patch

    😳 One sneaky plaintext byte is all it takes. Exim’s new “Dead.Letter” (CVE-2026-45185) triggers when a client sends a TLS close_notify mid-BDAT, then slips in a final \n. That single write hits a freed TLS buffer → corrupts heap allocator metadata on GnuTLS builds (4.97–4.99.2). XBOW calls it one of the highest-caliber bugs they’ve seen in Exim. Patch to 4.99.3 right now 👇

    Post summary

    Exim CVE-2026-45185 is a severe heap corruption bug caused by a single byte, with a patch available in version 4.99.3. No active exploitation or PoC details are provided.

    23511183022.7K
    1.9M followersView on X
  • FOFA@fofabot
    Patch

    ⚠️⚠️ CVE-2026-45185 (CVSS 9.8): Critical Exim mail-server vulnerability — patch or upgrade immediately. 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJFeGltLU1haWwtU2VydmVyIg%3D%3D 🎯6.0M+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="Exim-Mail-Server" 🔖Refer: https://exim.org/static/doc/security/EXIM-Security-2026-05-01.1/ https://thehackernews.com/2026/05/new-exim-bdat-vulnerability-exposes.html #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    The message announces CVE‑2026‑45185 as a critical Exim mail‑server flaw with a CVSS score of 9.8, urges immediate patch or upgrade, and provides vendor advisory and FOFA query links, but offers no exploit code or technical details.

    124054194.7K
    14.4K followersView on X
  • The Hacker News@TheHackersNews
    Patch

    🚨 Exim fixed CVE-2026-45185, a use-after-free flaw affecting versions 4.97 through 4.99.2 when built with GnuTLS. The BDAT parsing bug can cause heap corruption and potential code execution. Full details: https://thehackernews.com/2026/05/new-exim-bdat-vulnerability-exposes.html

    Post summary

    Exim has patched the use‑after‑free flaw CVE‑2026‑45185 affecting certain GnuTLS builds, with the fix already deployed; technical details and further risk information are provided in the linked article.

    022361732.6K
    1.9M followersView on X
  • XBOW@Xbow
    Disclosure

    XBOW discovered a critical vulnerability in Exim (CVE-2026-45185), a widely used mail server. https://bit.ly/42yKTmX Our security researcher @fede_k shares the story of its discovery and disclosure below.

    Post summary

    A researcher has reported a new critical vulnerability in Exim (CVE-2026-45185), but the post provides no further technical or exploit details.

    183531917.2K
    12.0K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Exim fixes a 9.8 severity RCE (CVE-2026-45185) affecting GnuTLS builds. A single-byte heap corruption allows for server takeover. Update to 4.99.3 now! #Exim #CyberSecurity #InfoSec #RCE #GnuTLS #SMTP #VulnerabilityAlert #SysAdmin #MailSecurity #CVE https://securityonline.info/exim-vulnerability-cve-2026-45185-gnutls-heap-corruption/ https://t.co/HXhNWitfaT

    Post summary

    Exim releases a fix for CVE‑2026‑45185, a critical Heap‑corruption RCE in GnuTLS, available in version 4.99.3.

    110137132.9K
    12.5K followersView on X
  • Netlas.io@Netlas_io
    Disclosure

    CVE-2026-45185: RCE in Exim, 9.8 rating 🔥 Vulnerability in Exim allows an unauthenticated network attacker to execute arbitrary code. 👉 https://nt.ls/0Wqux

    Post summary

    A new CVE (CVE‑2026‑45185) for Exim is disclosed, stating an unauthenticated network attacker can execute arbitrary code with a 9.8 severity rating.

    07024172.1K
    7.6K followersView on X
  • Hunter@HunterMapping
    PoC

    🚨Alert🚨 CVE-2026-45185 (CVSS 9.8) : New Exim BDAT Vulnerability Exposes GnuTLS Builds to Potential Code http://Execution.It affects versions from 4.97 up to and including 4.99.2. 🧐Detail :https://xbow.com/blog/dead-letter-cve-2026-45185-xbow-found-rce-exim 📊 3.7M+ Services are found on the http://hunter.how yearly. 🔗Hunter Link:https://hunter.how/list?searchValue=product.name%3D%22Exim%20smtpd%22 👇Query HUNTER : http://product.name="Exim smtpd" 📰Refer:https://www.exim.org/static/doc/security/EXIM-Security-2026-05-01.1/EXIM-Security-2026-05-01.1.txt https://www.openwall.com/lists/oss-security/2026/05/12/4 https://thehackernews.com/2026/05/new-exim-bdat-vulnerability-exposes.html #hunterhow #infosec #infosecurity #OSINT #Vulnerability

    Post summary

    High‑severity Exim vulnerability CVE‑2026‑45185 is highlighted with technical details, a link to a blog that likely hosts a proof‑of‑concept, but no active exploitation or patch information is provided.

    07026132.5K
    26.0K followersView on X
  • XBOW@Xbow
    Disclosure

    A newly disclosed Exim vulnerability, CVE-2026-45185 (“Dead.Letter”), highlights how a flaw in handling SMTP BDAT commands and TLS connection termination could create serious security risks in widely deployed email infrastructure. As covered by Ravie Lakshmanan in @TheHackersNews, the vulnerability was discovered and responsibly reported by XBOW. The flaw affects GnuTLS-based Exim builds and could enable heap corruption and potential remote code execution through BDAT message handling during TLS shutdown. Research like this reflects the depth of analysis required to uncover high-impact vulnerabilities before attackers do. Read the full article: https://bit.ly/4nzv60T

    Post summary

    The article discloses a new Exim flaw (CVE‑2026‑45185) that could lead to heap corruption and remote code execution via BDAT/TLS handling; it provides technical details but no PoC, exploit code, patch, or evidence of active exploitation.

    1612849.9K
    12.0K followersView on X
  • Brendan Dolan-Gavitt@moyix
    PoC

    The full post is here: https://xbow.com/blog/dead-letter-cve-2026-45185-xbow-found-rce-exim

    Post summary

    The post announces CVE‑2026‑45185, identifies an RCE in Exim, and links to a blog likely containing a proof‑of‑concept, but it does not report active exploitation or supply patches.

    13023102.6K
    33.2K followersView on X
  • XBOW@Xbow
    PoC

    XBOW found CVE-2026-45185, reported it responsibly, then used the disclosure window to test a harder question: How far can autonomous exploit development go against real-world native code? Full write-up here: https://bit.ly/42yKTmX https://t.co/un1blf4vC1

    Post summary

    XBOW discovered CVE-2026-45185 and shared a write‑up that likely contains a proof of concept, but no explicit exploit code, patch, or evidence of active exploitation is presented.

    1302391.9K
    12.0K followersView on X
  • Federico Kirschbaum@fede_k
    PoC

    Check out our write-up: http://xbow.com/blog/dead-letter-cve-2026-45185-xbow-found-rce-exim Credits to: @ChupitGood, @moyix & @Xbow https://t.co/VEYmrUvGAk

    Post summary

    The tweet links to a blog post detailing an RCE in Exim (CVE‑2026‑45185) and suggests a PoC is available, but provides no exploit code, patch info, or evidence of active exploitation.

    2102071.1K
    7.5K followersView on X
  • XBOW@Xbow
    Disclosure

    Email infrastructure remains one of the Internet’s highest-value attack surfaces. In @BleepinComputer, Bill Toulas covers XBOW’s discovery of CVE-2026-45185, a critical unauthenticated Exim RCE, and the crucial role AI tools play in helping security researchers to understand unfamiliar code and investigate vulnerabilities faster. Read on: https://bit.ly/3Rg6MoM

    Post summary

    The article reports the discovery of a critical unauthenticated XCOM RCE vulnerability in Exim (CVE‑2026‑45185) but does not mention PoCs, exploits, active usage, patches, or debunking.

    3101161.8K
    12.0K followersView on X
  • Ryan Dewhurst@ethicalhack3r
    Disclosure

    Supply Chain Attacks on a Patch Tuesday not enough for ya? Add a Remote Unauth Exim DoS/RCE🪄 CVE-2026-45185

    Post summary

    The tweet announces CVE‑2026‑45185, noting that it allows remote unauthenticated DoS and RCE on Exim, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    0001252.4K
    21.2K followersView on X
  • Federico Kirschbaum@fede_k
    General

    We found a critical bug in Exim, reported it, then spent 7 days racing an LLM to try to exploit it first. This is a first-hand story of dead.letter (CVE-2026-45185) and how the time between discovery and exploitation is shrinking from an exploit writer's perspective. 2/🧵

    Post summary

    The author reports discovering CVE-2026-45185 in Exim, reporting it, and attempting to be the first to exploit it within seven days, illustrating the decreasing time from discovery to exploitation.

    1001201.1K
    7.5K followersView on X
  • Leandro Barragan@lean0x2f
    Disclosure

    From XBOW labs 😊 https://xbow.com/blog/dead-letter-cve-2026-45185-xbow-found-rce-exim

    Post summary

    XBOW Labs announced a newly discovered RCE in Exim (CVE-2026-45185), providing the CVE ID and attack surface but no PoC, exploit details, or remediation guidance.

    00063379
    2.9K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-45185: Exim: Use-after-free https://www.openwall.com/lists/oss-security/2026/05/12/25 in BDAT (binary data transmission) body parsing path when using the GnuTLS backend. Can lead to heap corruption and potential code execution. Fixed in 4.99.3. https://x.com/Xbow/status/2054234664882020377

    Post summary

    The text announces the Exim use‑after‑free CVE-2026‑45185, details its impact, and notes that it has been fixed in version 4.99.3.

    010521.3K
    4.7K followersView on X
  • Ekoparty | Hacking everything@ekoparty
    Disclosure

    Charlas Main Track by @bancogalicia I EKO Buenos Aires 2026 🔥 🗣️ “Dead.Letter y el exploit writing moderno” dictada por Andrés Luksenberg. 🎯 Andrés Luksenberg encontró Dead.Letter (CVE-2026-45185), una vulnerabilidad pre-auth en Exim que permitía ejecución remota de código en servidores vulnerables. Los siete días entre el reporte y la publicación se convirtieron en una carrera caótica. De un lado, un agente intentaba desarrollar el exploit de forma autónoma. Del otro, yo trataba de llegar al mismo resultado trabajando con un LLM como asistente. La conclusión parecía clara: los modelos podían acelerar la lectura de código y resolver problemas con forma de CTF, pero explotar software real todavía exigía debugging, criterio e intervención humana. Sin embargo, en apenas tres meses el panorama cambió. Entonces, ¿en qué punto se encuentra hoy el proceso de exploit writing con LLMs? 🚀 En esta charla, Andrés va a reconstruir el bug, su explotación y los errores de aquel experimento, para luego contrastarlos con el estado actual del desarrollo de exploits para vulnerabilidades reales usando LLMs. Veremos qué partes del proceso ya pueden resolver, dónde siguen fallando y cómo está cambiando el trabajo del exploit writer. 🎙️ Esta charla será dictada en español. 📅 Ekoparty Buenos Aires | 7, 8 y 9 de octubre 2026 🎫 Comprá tu entrada ahora en http://ekoparty.org

    Post summary

    The passage outlines a conference talk that introduces and details the newly disclosed Exim RCE CVE‑2026‑45185, but it does not provide any PoC, exploit code, active exploitation evidence, or patch information.

    00070816
    25.7K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    メールサーバEximが重大(Critical)な脆弱性を修正。CVE-2026-45185 (Dead.Letter)はCVSSスコア9.8で、BDATメッセージボディ処理時の解放後メモリ使用。任意コード実行のおそれ。バージョン4.99.3で修正。 https://thehackernews.com/2026/05/new-exim-bdat-vulnerability-exposes.html

    Post summary

    Exim CVE-2026-45185 (Dead.Letter) is a critical memory‑use‑after‑free flaw with CVSS 9.8, but has already been fixed in version 4.99.3 and there is no evidence of active exploitation or a PoC.

    020401.0K
    7.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appeximexim---

Explore more