CVE-2026-66141: Exim

High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.

Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.

Affected products

  • Exim Exim: before 4.99.5 (fixed in 4.99.5)

Published 2026-07-24. Last modified 2026-08-17.