Critical Exim Mail Server Vulnerabilities Require Immediate Patching
Article Content
- •Exim version 4.99.2 released to fix four critical vulnerabilities.
- •Vulnerabilities could lead to server crashes and data leaks.
- •Immediate patching is recommended for all Exim mail server users.
The Exim mail server developers released version 4.99.2 on 2026-05-01 to address four critical vulnerabilities. These vulnerabilities could allow attackers to crash server connections, corrupt memory heaps, or leak sensitive system data through malicious DNS data. Exim is widely used as a message transfer agent, making these flaws particularly concerning for system administrators. Administrators are strongly advised to apply the patch immediately to mitigate potential risks. The vulnerabilities could have a significant impact on the stability and security of email services globally. Specific CVEs have not been disclosed in the articles, but the urgency of the situation is emphasized. The patch is now available, and administrators should prioritize its implementation to protect their systems.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…