Exim Mail Server Hit by 4 Security Flaws Enabling SMTP Smuggling and Heap Corruption
Exim Mail Server 4.100.1 patches critical out-of-bounds write and SMTP smuggling flaws that could allow remote code execution and message injection.
Exim maintainers released version 4.100.1 to patch four security flaws in the widely used mail transfer agent. The most critical is an out-of-bounds write vulnerability (GCVE-25-2026-09-50-1) in the Proxy Protocol v1 handler, affecting versions 4.83 through 4.100, which could lead to crashes and potential exploitation. The other three flaws enable SMTP smuggling, allowing attackers to inject messages by exploiting parsing inconsistencies between mail infrastructure components.
65