Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-67896

32
FAUCET Score

CVE-2025-67896 is a critical heap-based buffer overflow vulnerability affecting Exim versions prior to 4.99.1 when configured with non-default rate-limiting. This flaw allows a remote, unauthenticated attacker to execute arbitrary code with high impact on confidentiality, integrity, and availability, as reflected by its CVSS score of 9.8. Despite its severity, there is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.99, < 4.99.1CPE match
cpe:2.3:a:exim:exim:*:*:*:*:*:*:*:*
< 4.99.1CPE matchmatch criteria
cpe:2.3:a:exim:exim:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.0HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
HIGH
Availability Impact
LOW
Exploitability Score
2.2
Impact Score
4.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.41%
Probability of exploitation in next 30 days
EPSS Percentile
33.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0041 is in the 11th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (6)

boschvendor investigatingvia llm_extracted
citrix_adcvendor investigatingvia llm_extracted
View patch
esetvendor investigatingvia llm_extracted
View patch
giteavendor investigatingvia llm_extracted
View patch
googlevendor investigatingvia llm_extracted
rocketchatvendor investigatingvia llm_extracted

Vendor Advisories (7)

giteallm-gitea-6e4c4f94021d2e5f
Dec 17, 2025
redhatCVE-2025-67896Moderate

exim: Exim: Remote heap corruption vulnerability

Dec 14, 2025
googlellm-google-0f4e9e365a370137

Security Advisory for CVE-2025-67896

esetllm-eset-4d4cd0fffa1482f7
citrix_adcllm-citrix_adc-03b6a9d8475955fd
boschllm-bosch-8adfa2d519f62d79

Security Advisory for CVE-2025-67896

rocketchatllm-rocketchat-ba3ab7042635325b

References

openwall.com / lists/oss-security/2025/12/14/1
Mailing List
openwall.com / lists/oss-security/2025/12/18/3
Mailing List
exim.org / static/doc/security
Vendor Advisory
exim.org / static/doc/security/EXIM-Security-2025-12-09.1/report.txt
Vendor Advisory
openwall.com / lists/oss-security/2025/12/11/2
Mailing List