Exim

5 known vulnerabilities in Exim, 1 critical, 1 actively exploited, with patch priority, exploit likelihood and the news covering them.

Recently exploited

  • CVE-2019-10149 CVSS 9.8 critical · actively exploited Exim Mail Transfer Agent (MTA) Improper Input Validation

Latest vulnerabilities

  • CVE-2026-94057 CVSS 5.3 medium Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted…
  • CVE-2026-94056 CVSS 7.5 high Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data…
  • CVE-2026-94055 CVSS 5.3 medium Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.
  • CVE-2026-94054 CVSS 5.3 medium Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write.
  • CVE-2019-10149 CVSS 9.8 critical · actively exploited Exim Mail Transfer Agent (MTA) Improper Input Validation