SEPTEMBER 26, 2026
Live Feed
Back to database
Case File

CVE-2026-94054

HIGH · CVSS 7 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-09-19 · Last synced 2026-09-26

CyberRota Analysis

AI-Generated

Exim versions prior to 4.100.1 are vulnerable to an out-of-bounds write when the Proxy-Protocol is utilized with a maliciously controlled proxy. This vulnerability could allow an attacker to execute arbitrary code, potentially compromising the affected mail server. Organizations using Exim should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-94054
Severity
HIGH
CVSS
7
EPSS
0.27%

Original NVD Description

Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write.

Related CVEs

Other vulnerabilities affecting the same vendor(s)