Published on 7 August 2026
A critical use-after-free vulnerability has been discovered in the BDAT parser of Exim versions 4.97 to 4.99.2 (GnuTLS builds, the default on Debian/Ubuntu) (CVE-2026-45185, CVSS 9.8, alias: Dead.Letter). Unauthenticated attackers can corrupt the heap and achieve remote code execution via crafted SMTP BDAT commands. The patch is available in version 4.99.3. Exim is the world's most widely used mail transfer agent.