Exim maintainers released Exim 4.99.3 to fix a critical remotely reachable use-after-free flaw in the SMTP server’s BDAT body parsing path, tracked as CVE-2026-45185 and referred to as Dead.Letter. The vulnerability affects Exim 4.97 through 4.99.2/4.99.x when built with GnuTLS support and configured to advertise both STARTTLS and CHUNKING, and successful exploitation can cause heap corruption with potential remote code execution. Maintainers said Linux distributions received coordinated access to patches ahead of disclosure and urged users to upgrade immediately.
According to the advisory and follow-on reporting, the bug is triggered when a client sends a TLS close_notify before a BDAT transfer finishes and then sends a final cleartext byte over the same TCP connection, leaving Exim in an unsafe state. Exim said there are no effective mitigations short of upgrading, and fixed the issue in 4.99.3 by resetting the input-processing stack when TLS shutdown occurs during an active BDAT transfer. The flaw was reported by Federico Kirschbaum of XBOW security, with fuller technical details to be published under EXIM-Security-2026-05-01.1.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
By May 12, 2026, public reporting described the trigger condition for the flaw: a client can send a TLS close_notify before BDAT transfer completion and then send a final cleartext byte on the same TCP connection. This clarified how the vulnerability could lead to heap corruption and possible remote code execution on affected GnuTLS-based Exim deployments.
On 2026-05-11, Google Threat Intelligence Group reportedly described the first documented in-the-wild zero-day exploit built with material AI assistance. The report said the Python-based 2FA bypass targeted a widely deployed open-source administration tool and had been patched with the vendor before the campaign launched.
The Exim BDAT use-after-free flaw reported by XBOW was assigned identifier CVE-2026-45185. XBOW's published disclosure timeline places the CVE assignment on May 10, 2026, ahead of the public technical release.
Exim publicly disclosed advisory EXIM-Security-2026-05-01.1 and warned that there are no mitigations short of upgrading to 4.99.3 or later. The maintainers also noted that Linux distributions had already received coordinated access to patches and that fuller technical details would be published separately.
On May 1, 2026, Exim maintainers released security update 4.99.3 to fix CVE-2026-45185, also called Dead.Letter. The patch resets the input processing stack when TLS shutdown occurs during an active BDAT transfer, preventing heap corruption and potential code execution.
Federico Kirschbaum of XBOW discovered and reported a critical remotely reachable use-after-free flaw in Exim's BDAT body parsing path. The issue affects Exim 4.97 through 4.99.2/4.99.x when built with GnuTLS support and advertising both STARTTLS and CHUNKING.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
13 references tracked. Mallory keeps watching after this page renders.
hivepro.com
Open sourcesupport.cpanel.net
Open sourcescworld.com
Open sourcethecyberexpress.com
Open sourceopennet.me
Open sourceopenwall.com
Open sourceseclists.org
Open sourcexbow.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.