PatchSiren cyber security CVE debrief
CVE-2026-94057 Exim CVE debrief
SMTP smuggling vulnerability in Exim before 4.100.1 allows crafted data to cause mismatch between received and sent messages. This issue arises from the improper handling of data sent after a rejection during DATA processing, potentially leading to message mismatch and security risks. Defenders and administrators should assess the impact and take necessary actions to secure Exim installations. The vulnerability has a medium severity and requires immediate attention to prevent potential SMTP smuggling attacks.
- Vendor
- Exim
- Product
- Unknown
- CVSS
- MEDIUM 4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-19
- Original CVE updated
- 2026-09-19
- Advisory published
- 2026-09-19
- Advisory updated
- 2026-09-19
Who should care
Defenders and administrators of Exim installations should verify their version and assess exposure to SMTP smuggling attacks. They should also consider implementing compensating controls to detect and prevent SMTP smuggling attacks. Additionally, security teams and vulnerability management teams should review the vulnerability and provide guidance on mitigation and remediation.
Why it matters
CVE-2026-94057 is a medium-severity vulnerability in Exim before 4.100.1 that allows SMTP smuggling, potentially causing message mismatch. Defenders and administrators of Exim installations should verify their version and assess exposure to SMTP smuggling attacks.
- Verify Exim version and upgrade to 4.100.1 or later if necessary to prevent SMTP smuggling
- Assess exposure to SMTP smuggling attacks and monitor for suspicious SMTP activity
- Implement compensating controls to detect and prevent SMTP smuggling attacks
Technical summary
Exim before 4.100.1 allows SMTP smuggling due to crafted data sent after a rejection during DATA processing, potentially causing message mismatch. This vulnerability has a CVSS score of 4 and a medium severity. The issue is related to the improper handling of SMTP data, which can lead to security risks if not addressed promptly. Defenders and administrators of Exim installations should verify their version and assess exposure to SMTP smuggling attacks.
Defensive priority
Verify Exim version and assess exposure to SMTP smuggling
Recommended defensive actions
- Verify Exim version and upgrade to 4.100.1 or later if necessary
- Assess exposure to SMTP smuggling attacks
- Monitor for suspicious SMTP activity
Evidence notes
Limited evidence available; official CVE and NVD records provide basic vulnerability information. The CVE record was published on 2026-09-19T23:17:11.257Z and has not been modified since then. The NVD detail page offers source-specific vulnerability assessment. Additional verification tasks are recommended to confirm affected scope and severity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-94057 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-94057
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-94057 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-94057
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://lists.exim.org/lurker/message/20260918.121220.0f87338e.en.html
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.