Email Security

Critical Exim Flaw Allows Attackers to Deliver Malicious Executables to Mailboxes

Successful exploitation could allow attackers to deliver executable attachments to inboxes.

Successful exploitation could allow attackers to deliver executable attachments to inboxes.

A critical vulnerability in over 1.5 million internet-accessible Exim mail transfer agent (MTA) installations potentially allows attackers to deliver malicious executables to user mailboxes, Censys warns.

The issue, tracked as CVE-2024-39929 (CVSS score of 9.1) and impacting RFC 2231 header parsing, results in filenames being incorrectly parsed, which could allow remote attackers to bypass the filename extension-blocking protection mechanisms.

Successful exploitation of the security defect could allow attackers to deliver executable attachments to inboxes, which could lead to code execution and system compromise, if the user opens the attachment.

Proof-of-concept (PoC) code targeting the bug has been released publicly, but no exploitation attempts have been observed yet, Censys says.

According to the attack surface management firm, of the over 6.5 million SMTP mail servers accessible from the internet it has discovered, roughly 4.8 million are running Exim.

“As of July 10, 2024, Censys observes 1,567,109 publicly exposed Exim servers running a potentially vulnerable version (4.97.1 or earlier), concentrated mostly in the United States, Russia, and Canada,” the cybersecurity firm says.

Advertisement. Scroll to continue reading.

The vulnerability was disclosed last month and was addressed in Exim MTA version 4.98, but most internet-facing servers remain unpatched, Censys warns. As of July 10, only 82 Exim MTA installations were running a patched release.

Censys has released resources to help organizations identify public-facing Exim instances running a potentially vulnerable release, urging them to update to a patched iteration as soon as possible.

Vulnerabilities in Exim, which is widely used for receiving and relying emails, are known to have been exploited by threat actors in the wild.

Related: Vulnerabilities Exposed Millions of Cox Modems to Remote Hacking

Related: Unpatched Exim Vulnerabilities Expose Many Mail Servers to Attacks

Related: Over 4,000 Vulnerable Pulse Connect Secure Hosts Exposed to Internet

Related Content

Vulnerabilities

Adobe and Nvidia each published several advisories, including ones that address critical vulnerabilities in their products.

Vulnerabilities

Most of the flaws were discovered by Google using AI, but researchers are still discovering high-value Chrome vulnerabilities.

Vulnerabilities

CVE-2026-60004 is a remote code execution vulnerability patched by Gitea developers in late July with the release of version 1.27.1.

Vulnerabilities

CVE-2026-61979 and CVE-2026-15981 are authentication bypass vulnerabilities affecting the MiniOrange SAML 2.0 SSO plugin.

Vulnerabilities

The vulnerability is tracked as CVE-2026-21962 and it has been widely exploited by threat actors against WebLogic servers.

Vulnerabilities

More than 200 vulnerabilities have been patched to date this year, compared to only 16 in 2025 and 22 in 2024. 

Vulnerabilities

The type confusion bug can lead to V8 sandbox escape and control-flow hijacking of the host process.

Cloud Security

A total of 22 patches were releaased, a majority for code execution, privilege escalation, and information disclosure vulnerabilities.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version