Summary
XBOW’s Dead.Letter write-up describes CVE-2026-45185 as a critical unauthenticated Exim remote-code-execution vulnerability in the GnuTLS BDAT path. Public downstream records identify Exim as affected and point to Exim security advisory material and fixes.
Attribution
This is labeled self-reported because XBOW provides the AI discovery narrative. The vulnerability itself is not only self-reported: Exim, Ubuntu, and CVE records corroborate the public security issue and remediation trail.
References
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.