Exim CVE-2026-45185 'Dead.Letter': Critical RCE in GnuTLS Builds

Short & clear answers
Frequently asked questions about this incident
Am I affected by the Exim vulnerability CVE-2026-45185?
Affected versions are Exim 4.97 through 4.99.2 in GnuTLS builds, which are the default on Debian, Ubuntu, and Debian-based distributions (e.g., Linux Mint, Raspberry Pi OS). Not affected are Exim builds using OpenSSL (typical on RHEL, CentOS, Fedora, SUSE) and managed services such as Google Workspace or Microsoft 365. You can check your TLS library with the command 'exim -bV'.
What do I need to do right now to protect myself?
Update Exim to version 4.99.3 immediately via your distribution's package manager and restart the service afterward. Debian users should upgrade to the patched packages (stable 4.98.2-1+deb13u2, oldstable 4.96-15+deb12u9, oldoldstable 4.94.2-7+deb11u5). According to Exim and CERT Uganda there is no configuration workaround – only the update fixes the issue.
How dangerous is this vulnerability?
The vulnerability is rated critical with a CVSS score of 9.8. Unauthenticated attackers can corrupt the heap via crafted SMTP BDAT commands and achieve remote code execution. An attacker only needs to be able to establish a TLS connection and use the CHUNKING (BDAT) SMTP extension.
Is there a temporary workaround if I can't update immediately?
No. Both the Exim maintainers and CERT Uganda explicitly state that no configuration workaround exists. The only effective measure is upgrading to Exim 4.99.3.
Do I have to report this incident under GDPR?
If your Exim server was successfully attacked and personal data could be affected, a reporting obligation under Art. 33 GDPR may apply. Check your server logs for suspicious BDAT activity and consult your data protection officer if in doubt. Merely running the vulnerable version without a compromise generally does not trigger a reporting obligation.
More security news
You might also be interested in
Critical Elementor Pro Flaw: Attackers Can Fully Take Over WordPress Sites
A file upload bug in Elementor Pro up to 4.2.1 allows RCE without login. Version 4.2.2 fixes the flaw – update now!
Pods Plugin: Critical Flaw Enables Admin Takeover, No Login
A critical flaw in the WordPress plugin Pods lets attackers overwrite admin passwords without login. Over 100,000 sites are affected.
miniOrange SAML SSO: Critical Bypass Turns Attackers Into Admins
Two critical auth bypasses in the miniOrange SAML SSO plugin allow forged SAML assertions—up to full WordPress admin access.