CVE-2026-94054: High severity Exim Exim vulnerability
Published Sep 19, 2026
·Updated
Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write.
Affected Software
1 affected component
Exim Exim<4.100.1
Event History
Sep 19, 2026
CVE Published
via MITRE·10:46 PM
Data Sourced
via MITRE·10:46 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are exposed?
Exim deployments before 4.100.1 are affected when they use Proxy-Protocol with a proxy that an attacker can control.
2
Does an attacker need an account or user interaction to exploit this?
No. The supplied vector indicates network access is required, with no privileges or user interaction required; however, exploitation has high attack complexity.