Exim Remote Code Execution Vulnerability
Release Date:
13 May 2026
5065
Views
RISK: Medium Risk
TYPE: Security software and application - Security Software & Appliance

A vulnerability has been identified in Exim. A remote attacker could exploit this vulnerability to trigger denial of service condition and remote code execution on the targeted system.
Impact
- Remote Code Execution
- Denial of Service
System / Technologies affected
- All Exim versions from 4.97 up to and including 4.99.2 are affected.
This vulnerability only impacts builds that use USE_GNUTLS=yes. Builds using OpenSSL or other TLS libraries are not affected.
Solutions
Before installation of the software, please visit the vendor web-site for more details.
- Update to Exim version 4.99.3
Vulnerability Identifier
Source
Related Link
Related Tags
Share with
