<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>RCE on kalfaoglu.net</title><link>https://blog.kalfaoglu.net/tags/rce/</link><description>Recent content in RCE on kalfaoglu.net</description><generator>Hugo</generator><language>en</language><lastBuildDate>Sun, 21 Jun 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://blog.kalfaoglu.net/tags/rce/index.xml" rel="self" type="application/rss+xml"/><item><title>Dead.Letter (CVE-2026-45185): Unauthenticated RCE in Exim GnuTLS Builds — Patch Now</title><link>https://blog.kalfaoglu.net/posts/2026-06-21-exim-dead-letter-cve-2026-45185-en/</link><pubDate>Sun, 21 Jun 2026 00:00:00 +0000</pubDate><guid>https://blog.kalfaoglu.net/posts/2026-06-21-exim-dead-letter-cve-2026-45185-en/</guid><description>&lt;p&gt;If you&amp;rsquo;re running Exim on Debian or Ubuntu and haven&amp;rsquo;t patched in the past five weeks, there&amp;rsquo;s a reasonable chance your mail server is remotely exploitable by anyone who can open a TLS connection to port 25. No credentials required. No special tooling. Standard SMTP commands.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45185"&gt;CVE-2026-45185&lt;/a&gt;, nicknamed &lt;strong&gt;Dead.Letter&lt;/strong&gt;, is a use-after-free vulnerability in Exim&amp;rsquo;s BDAT message parsing path. CVSS score: 9.8 Critical. Fixed in Exim 4.99.3, released May 12, 2026. If you haven&amp;rsquo;t checked your version since then, now would be a good time.&lt;/p&gt;</description></item></channel></rss>