Vendor

Exim

As of , 5 Exim vulnerabilities are on CISA's list of exploited vulnerabilities, 1 of them used in ransomware campaigns; 0 were added in 2026. Patch first: CVE-2010-4344.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2010-4344Heap-Based Buffer OverflowExim EximPatch this weekMetasploit module; EPSS 0.72; verified Exploit-DB entry0.72
2CVE-2019-10149Improper Input ValidationExim Mail Transfer Agent (MTA)Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry0.99
3CVE-2010-4345Privilege EscalationExim EximPatch this weekMetasploit module; verified Exploit-DB entry0.18
4CVE-2018-6789Buffer OverflowExim EximPatch this weekRansomware use; EPSS 0.820.82
5CVE-2019-16928Out-of-bounds WriteExim Exim Internet MailerPatch soon0.42

Products

  • Exim3 entries
  • Exim Internet Mailer1 entry
  • Mail Transfer Agent (MTA)1 entry

Added each year

12342021: 1120212022: 4420222023: nonenone20232024: nonenone20242025: nonenone20252026: nonenone2026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20211
20224
2023none
2024none
2025none
2026none

Used in ransomware