Researchers at the National Institute of Standards and Technology (NIST) have revealed critical vulnerabilities in the popular Exim mail server. The findings show that, under certain circumstances, remote attackers could gain complete control of vulnerable systems, putting organizations and service providers worldwide at serious risk.

Which versions are affected?
The security issues concern Exim version 4.99, when it is configured with SQLite hints database.
While not all Exim installations are affected, experts point out that many production infrastructures use exactly these settings, often without administrators being aware of the potential risk.
Exim mail server: Two critical vulnerabilities under the microscope
The NIST research team has identified two separate, but extremely serious security vulnerabilities related to the SQLite implementation in Exim.
See also: Beware! Zero-day vulnerability in WatchGuard Firebox firewalls
The first concerns an incomplete SQL injection fix, known as CVE-2025-26794. The issue arises from the incorrect handling of single-quote characters in database queries. In practice, this allows attackers to inject malicious SQL code via specially crafted SMTP commands, using email addresses containing SQL injection payloads.
The second vulnerability is even more concerning on a technical level. It is a heap buffer overflow, which is caused when unvalidated fields from the database are used as array boundaries. When processing this data by the bloom filter code, the code can write far beyond the allowed memory limits.

Accurate memory corruption and possible attack scenarios
According to the researchers, the above can lead to memory corruption, including the ability to target specific heap locations and write arbitrary byte values.
While a fully functional remote code execution (RCE) has yet to be demonstrated, experts warn that the level of control offered by this vulnerability is particularly dangerous. Given enough time, expertise, and resources, a determined attacker could bypass modern defenses and achieve a complete system compromise.
See also: React2Shell: The Log4j moment for front end development
When are loopholes exploitable?
The vulnerabilities require specific configurations. Mail servers must be compiled with SQLite support and use rate-limited Access Control Lists, which incorporate data that an attacker can control, such as sender addresses.
Particularly dangerous are settings that use the “per_addr” function with explicit sender address keys or “unique” parameters based on values derived from the SMTP session.
Why modern defenses are not enough
The researchers were able to demonstrate successful heap corruption and memory manipulation, but they did not complete a full RCE attack, due to mechanisms such as ASLR (Address Space Layout Randomization). However, the history of software security shows that such protections often fail in the face of complex exploit chains.
That's why the community is treating the findings as a high priority issue.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Remedial actions and recommendations
Exim maintainers have already been notified and are working on fixes. Suggested measures include proper single quote escaping to prevent SQL injection and strict validation of database field sizes before they are used as array boundaries.
See also: UEFI vulnerability allows DMA attacks on ASRock, ASUS, GIGABYTE, MSI motherboards
Until official updates are released, system administrators are advised to consider temporary solutions, such as disabling SQLite hints support or restricting ACL ratelimits based on sender addresses.
Coordinated disclosure for security purposes
The NIST research team follows a coordinated disclosure process, giving developers the necessary time to fix problems before all the technical details. In an era where attacks on email infrastructure are increasing, timely response and proper information remain the most powerful weapon of defense.
