Exim maintainers and downstream vendors disclosed and patched multiple vulnerabilities affecting the mail transfer agent, including a blind SQL injection issue tied to SQLite-backed hints databases, a related incomplete fix that left the injection path reachable in later code, and a heap buffer overflow in ratelimit handling. The SQL injection stemmed from attacker-controlled keys being interpolated into SQLite queries without escaping single quotes, while the heap overflow was caused by using an unvalidated bloom_size value from database records as the bound for a fixed 40-byte bloom buffer. The issues affected deployments using specific Exim configurations such as SQLite hints databases and ratelimit ACLs with attacker-influenced sender data.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
A SUSE Bugzilla entry identified CVE-2026-45185 as a remotely reachable use-after-free vulnerability in Exim's BDAT body parsing path. The reference establishes the flaw's existence and affected component, though it does not provide exploitation or patch details.
An oss-security post announced Exim security release 4.99.3. While the provided reference does not include the full advisory text, it indicates a coordinated upstream release to address Exim security flaws.
An Exim security report stated that Andrew Fasano of NIST had privately disclosed two vulnerabilities in Exim 4.99's SQLite-based hints database implementation: an incomplete fix for CVE-2025-26794 and a separate heap buffer overflow in ratelimit handling. The report included technical root-cause details, proof-of-concept exploitation notes, and recommendations for parameterized queries and bounds validation.
cPanel issued a product advisory warning that multiple vulnerabilities had been reported for Exim. The provided reference does not include technical details, but it marks a vendor response acknowledging the security issues.
A public GitHub write-up described CVE-2025-26794 as a blind SQL injection vulnerability in Exim 4.98 affecting the SQLite DBM-related functionality. This appears to be the first public reference in the provided sources to the issue and its exploit details.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
bugzilla.suse.com
Open sourceopenwall.com
Open sourcecode.exim.org
Open sourcesupport.cpanel.net
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.