PatchSiren cyber security CVE debrief
CVE-2026-45185 cPanel CVE debrief
CVE-2026-45185, also called Dead.Letter, is described as a use-after-free in Exim BDAT message body parsing when TLS is handled by GnuTLS. cPanel’s official advisory states its Exim build does not set USE_GNUTLS, depends on OpenSSL instead, and is not affected.
- Vendor
- cPanel
- Product
- cPanel/WHM
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-12
- Original CVE updated
- 2026-05-28
- Advisory published
- 2026-05-12
- Advisory updated
- 2026-05-28
Who should care
cPanel/WHM administrators, Exim maintainers, and operators of environments that may build or package Exim with GnuTLS support. For standard cPanel/WHM systems, the vendor says this issue does not apply.
Technical summary
The vendor describes the flaw as a use-after-free in Exim’s binary data transmission (BDAT) message body parsing, triggered in the GnuTLS TLS path. cPanel says its Exim builds do not explicitly enable USE_GNUTLS and use OpenSSL, so the affected code path is not present in their builds.
Defensive priority
Low for standard cPanel/WHM installations; no immediate remediation is needed based on the vendor advisory.
Recommended defensive actions
- No immediate action is required for standard cPanel/WHM systems, per the vendor advisory.
- If you maintain custom Exim builds, verify whether USE_GNUTLS is enabled and whether your TLS stack matches the affected GnuTLS path.
- Track the official cPanel advisory and the CVE record for any future updates or scope changes.
Evidence notes
This debrief is based on the cPanel official security article for CVE-2026-45185, published 2026-05-12 and updated 2026-05-15, which states cPanel builds use OpenSSL and are not affected. The CVE record and NVD detail are linked as official references, but the impact assessment here follows the vendor’s stated scope.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-45185 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-45185
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-45185 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-45185
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Vendor advisory source
Unverified legacy reference
URL: https://support.cpanel.net/hc/en-us/articles/40422058130967-Security-CVE-2026-45185-Dead-Letter
cpanel_changelog_rss
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.