Impact of Exim Use-After-Free Vulnerability (CVE-2026-45185) on Email Security.cloud
search cancel

Impact of Exim Use-After-Free Vulnerability (CVE-2026-45185) on Email Security.cloud

book

Article ID: 444392

calendar_today

Updated On:

Products

Email Security.cloud

Issue/Introduction

An inquiry was raised following the National Critical Information Infrastructure Protection Centre (NCIIPC) advisory (VA-2026-05-14-034) regarding a critical Use-After-Free vulnerability in Exim mail transfer agents.
This article provides a security assessment regarding the impact of CVE-2026-45185 on ESS platform.

Environment

Email Security.cloud (ESS)

Cause

CVE-2026-45185 is a critical vulnerability (CVSS 9.8) affecting Exim versions 4.97 through 4.99.x when configured with GnuTLS support, STARTTLS enabled, and SMTP CHUNKING advertised. This can lead to heap corruption and potential Remote Code Execution (RCE).

Resolution

Email Security.cloud is not affected by CVE-2026-45185