PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-45185 cPanel CVE debrief

CVE-2026-45185, also called Dead.Letter, is described as a use-after-free in Exim BDAT message body parsing when TLS is handled by GnuTLS. cPanel’s official advisory states its Exim build does not set USE_GNUTLS, depends on OpenSSL instead, and is not affected.

Vendor
cPanel
Product
cPanel/WHM
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-12
Original CVE updated
2026-05-28
Advisory published
2026-05-12
Advisory updated
2026-05-28

Who should care

cPanel/WHM administrators, Exim maintainers, and operators of environments that may build or package Exim with GnuTLS support. For standard cPanel/WHM systems, the vendor says this issue does not apply.

Technical summary

The vendor describes the flaw as a use-after-free in Exim’s binary data transmission (BDAT) message body parsing, triggered in the GnuTLS TLS path. cPanel says its Exim builds do not explicitly enable USE_GNUTLS and use OpenSSL, so the affected code path is not present in their builds.

Defensive priority

Low for standard cPanel/WHM installations; no immediate remediation is needed based on the vendor advisory.

Recommended defensive actions

  • No immediate action is required for standard cPanel/WHM systems, per the vendor advisory.
  • If you maintain custom Exim builds, verify whether USE_GNUTLS is enabled and whether your TLS stack matches the affected GnuTLS path.
  • Track the official cPanel advisory and the CVE record for any future updates or scope changes.

Evidence notes

This debrief is based on the cPanel official security article for CVE-2026-45185, published 2026-05-12 and updated 2026-05-15, which states cPanel builds use OpenSSL and are not affected. The CVE record and NVD detail are linked as official references, but the impact assessment here follows the vendor’s stated scope.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-45185 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-45185

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-45185 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-45185

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Vendor advisory source

    Unverified legacy reference

    URL: https://support.cpanel.net/hc/en-us/articles/40422058130967-Security-CVE-2026-45185-Dead-Letter

    cpanel_changelog_rss

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.