Skip to content
Critical Exim Vulnerabilities Affecting Ubuntu and Debian Systems

Critical Exim Vulnerabilities Affecting Ubuntu and Debian Systems

First seen 28 Sep 2026, 19:09 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 28, 2026 at 20:08 UTC

Multiple critical vulnerabilities in Exim, a mail transport agent, have been disclosed, affecting Ubuntu 26.04 LTS and Debian systems. These include CVE-2026-94054, CVE-2026-94055, and CVE-2026-94056, all published on 2026-09-19. The vulnerabilities allow remote code execution, denial of service, and information disclosure through various attack vectors, including out-of-bounds writes and use-after-free conditions. CISA has confirmed exploitation of these vulnerabilities, urging system administrators to apply the necessary patches immediately. The affected Exim versions include 4.99.1-1ubuntu1.5 for Ubuntu and 4.98.2-1+deb13u5 for Debian. Users are advised to update their systems to mitigate these risks. The vulnerabilities primarily impact mail servers using Exim configured with certain settings.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-19
CVE-2026-94054, CVE-2026-94055, CVE-2026-94056 published
Multiple critical vulnerabilities in Exim were disclosed, affecting various Linux distributions.
Linuxsecurity
2026-09-27
Debian releases patch for Exim vulnerabilities
Debian announced updates for Exim to address critical vulnerabilities, recommending users to upgrade their packages.
Linuxsecurity
2026-09-28
CISA confirms exploitation of Exim vulnerabilities
CISA issued a warning about the active exploitation of vulnerabilities in Exim, urging immediate action.
Linuxsecurity

More articles in this cluster (2)

Following this threat?

Track Ubuntu and CVE-2026-94054 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed