Exim is a widely deployed open-source mail transfer agent that handles message routing and delivery across many server environments, placing it in a critical position within email infrastructure despite its narrow product focus. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and have demonstrated a moderate tendency toward confirmed in-the-wild exploitation and public exploit availability, reflecting both the attack surface inherent to network-facing mail processing and the incentive for widespread weaponization. The recurring exposure concentrates on memory-safety and concurrency issues—out-of-bounds writes and reads, use-after-free conditions, and race conditions in shared resource handling—that are characteristic of Exim's C codebase and its role parsing untrusted message content from the network. Defenders should treat Exim updates as urgent and maintain strict visibility over internet-reachable instances, as flaws in mail servers have historically propagated rapidly across deployed infrastructure. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Exim over time
Signals from CVEs in this vendor scope (65 CVEs).
65 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-10149CRITICAL A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command exec | Jun 5, 2019 | 9.8 | 98 | YES | YES |
CVE-2018-6789CRITICAL An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer overflow may happen. This can be used to exec | Feb 8, 2018 | 9.8 | 97 | YES | YES |
CVE-2010-4344CRITICAL Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MA | Dec 14, 2010 | 9.8 | 97 | YES | YES |
CVE-2019-16928CRITICAL Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-based buffer overflow in string_vformat in string.c involving | Sep 27, 2019 | 9.8 | 86 | YES | NO |
CVE-2010-4345HIGH Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that cont | Dec 14, 2010 | 7.8 | 86 | YES | YES |
CVE-2025-26794CRITICAL Exim 4.98 before 4.98.1, when SQLite hints and ETRN serialization are used, allows remote SQL injection. (Resolving SQL injection requires an update to 4.99.1 in certain non-defaul | Feb 21, 2025 | 9.8 | 74 | NO | NO |
CVE-2017-16944HIGH The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial of service (infinite loop and stack exhaustion) via vectors | Nov 25, 2017 | 7.5 | 71 | NO | YES |
CVE-2020-28018CRITICAL Exim 4 before 4.94.2 allows Use After Free in smtp_reset in certain situations that may be common for builds with OpenSSL. | May 6, 2021 | 9.8 | 62 | NO | NO |
CVE-2020-28019HIGH Exim 4 before 4.94.2 has Improper Initialization that can lead to recursion-based stack consumption or other consequences. This occurs because use of certain getc functions is mish | May 6, 2021 | 7.5 | 56 | NO | NO |
CVE-2017-16943CRITICAL The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via v | Nov 25, 2017 | 9.8 | 56 | NO | NO |
Signals from CVEs in this vendor scope (65 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Exim.
Media articles that mention a CVE ID that affects a product developed by Exim — matched by CVE ID, not by vendor name.