Security News

Cybersecurity news aggregator

🔓
HIGH Vulnerabilities Gentoo GLSA

GLSA 202608-07: Exim: Multiple Vulnerabilities

Multiple vulnerabilities in Exim, including one allowing arbitrary code execution, affect versions prior to 4.99.4, with one high-severity issue (CVE-2025-30232, CVSS 8.1) impacting versions 4.96 through 4.98.1. The definitive fix requires upgrading to Exim version 4.99.4 or later, as no workaround is currently available. Administrators should prioritize patching due to the combination of local and remote exploitability and the high severity of the most critical flaw.
Read Full Article →

Multiple vulnerabilities have been found in Exim, the worst of which allows arbitrary code execution. Affected packages Package mail-mta/exim on all architectures Affected versions < 4.99.4 Unaffected versions >= 4.99.4 Background Exim is a message transfer agent (MTA) designed to be a a highly configurable, drop-in replacement for sendmail. Description Multiple vulnerabilities have been discovered in Exim. Please review the CVE identifiers referenced below for details. Impact Please review the referenced CVE identifiers for details. Workaround There is no known workaround at this time. Resolution All Exim users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=mail-mta/exim-4.99.4" References CVE-2024-39929 CVE-2025-30232 CVE-2026-40684 CVE-2026-40685 CVE-2026-40686 CVE-2026-40687 CVE-2026-45185 Release date August 14, 2026 Latest revision August 14, 2026: 1 Severity high Exploitable local and remote Bugzilla entries 938214 952139 974785

Share this article