CVE-2026-43964: Postfix

High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.

Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.

Affected products

  • Postfix Postfix: before 3.8.16 (fixed in 3.8.16); from 3.9.0, before 3.9.10 (fixed in 3.9.10); from 3.10.0, before 3.10.9 (fixed in 3.10.9)

Published 2026-05-04. Last modified 2026-08-20.