SEPTEMBER 26, 2026
Live Feed
Back to database
Case File

CVE-2026-94057

MEDIUM · CVSS 4 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-09-19 · Last synced 2026-09-26

CyberRota Analysis

AI-Generated

Exim versions prior to 4.100.1 are vulnerable to SMTP smuggling attacks, where an attacker can manipulate the message flow such that the received message diverges from the sent message, exploiting crafted data sent post-rejection during the DATA processing phase. This vulnerability could lead to unauthorized message delivery or data leakage, making it critical for organizations using affected versions of Exim to prioritize patching. System administrators and security teams managing email servers should address this issue promptly to mitigate potential exploitation risks.

CVE
CVE-2026-94057
Severity
MEDIUM
CVSS
4
EPSS
0.20%

Original NVD Description

Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent after a rejection during DATA processing.

Related CVEs

Other vulnerabilities affecting the same vendor(s)