PoC Index

CVE-2025-26794

CRITICAL 9.8EPSS 77.2%

Exim 4.98 before 4.98.1, when SQLite hints and ETRN serialization are used, allows remote SQL injection.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
77.17% chance of exploitation in the next 30 days, 100th percentile
Published
2025-02-21
Updated
2025-12-18

Proof-of-concept exploits (3)

References

Related