PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-94057 Exim CVE debrief

SMTP smuggling vulnerability in Exim before 4.100.1 allows crafted data to cause mismatch between received and sent messages. This issue arises from the improper handling of data sent after a rejection during DATA processing, potentially leading to message mismatch and security risks. Defenders and administrators should assess the impact and take necessary actions to secure Exim installations. The vulnerability has a medium severity and requires immediate attention to prevent potential SMTP smuggling attacks.

Vendor
Exim
Product
Unknown
CVSS
MEDIUM 4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-19
Original CVE updated
2026-09-19
Advisory published
2026-09-19
Advisory updated
2026-09-19

Who should care

Defenders and administrators of Exim installations should verify their version and assess exposure to SMTP smuggling attacks. They should also consider implementing compensating controls to detect and prevent SMTP smuggling attacks. Additionally, security teams and vulnerability management teams should review the vulnerability and provide guidance on mitigation and remediation.

Why it matters

CVE-2026-94057 is a medium-severity vulnerability in Exim before 4.100.1 that allows SMTP smuggling, potentially causing message mismatch. Defenders and administrators of Exim installations should verify their version and assess exposure to SMTP smuggling attacks.

  • Verify Exim version and upgrade to 4.100.1 or later if necessary to prevent SMTP smuggling
  • Assess exposure to SMTP smuggling attacks and monitor for suspicious SMTP activity
  • Implement compensating controls to detect and prevent SMTP smuggling attacks

Technical summary

Exim before 4.100.1 allows SMTP smuggling due to crafted data sent after a rejection during DATA processing, potentially causing message mismatch. This vulnerability has a CVSS score of 4 and a medium severity. The issue is related to the improper handling of SMTP data, which can lead to security risks if not addressed promptly. Defenders and administrators of Exim installations should verify their version and assess exposure to SMTP smuggling attacks.

Defensive priority

Verify Exim version and assess exposure to SMTP smuggling

Recommended defensive actions

  • Verify Exim version and upgrade to 4.100.1 or later if necessary
  • Assess exposure to SMTP smuggling attacks
  • Monitor for suspicious SMTP activity

Evidence notes

Limited evidence available; official CVE and NVD records provide basic vulnerability information. The CVE record was published on 2026-09-19T23:17:11.257Z and has not been modified since then. The NVD detail page offers source-specific vulnerability assessment. Additional verification tasks are recommended to confirm affected scope and severity.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-94057 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-94057

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-94057 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-94057

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.