CVE-2020-28018: Exim

Critical severity, CVSS 9.8. EPSS: 56.5% chance of exploitation in the next 30 days.

Exim 4 before 4.94.2 allows Use After Free in smtp_reset in certain situations that may be common for builds with OpenSSL.

Affected products

  • Exim Exim: from 4.90, before 4.94.2 (fixed in 4.94.2)

Published 2021-05-06. Last modified 2026-06-17.