Wednesday, May 13, 2026Curated by Daniel MiesslerOpen Surface →

9.8 Critical Alert: One-Byte Heap Corruption in Exim Exposes Global Mail Servers to Takeover

Exim’s GnuTLS path has a one-byte heap corruption bug. CVE-2026-45185 affects versions 4.97 through 4.99.2 and can reach allocator metadata. OpenSSL builds are unaffected, but GnuTLS servers need attention now. Upgrade to 4.99.3 and check exposed mail servers immediately.

Key points
Read original at Daily CyberSecurity →Open the full Surface feed →← Back to all news

This is one of fifty stories I surfaced this week from Surface — a tiny slice of the full feed.

More from the CYBER desk
Foreign Affairs Magazine
America Has Lost Its Leverage Over China
Daily CyberSecurity
Exploit Code Released: Public PoC Dumps for Windows BitLocker Bypass and SYSTEM Elevation Zero-Days
Hacker News Frontpage 24+
Deterministic Fully-Static Whole-Binary Translation Without Heuristics