All findings

CVE-2026-45185 critical

XBOW reports unauthenticated Exim RCE in Dead.Letter disclosure

XBOW says it discovered CVE-2026-45185, a critical unauthenticated Exim remote-code-execution vulnerability in the GnuTLS BDAT path, and Exim/Ubuntu/CVE records corroborate the public issue.

Bug class
GnuTLS BDAT use-after-free remote code execution
Affected codebase
Exim
Credited system
XBOW
Disclosed
May 12, 2026
Attribution
Self-reported attribution
Severity
critical
Source status: XBOW's write-up supplies the AI-system attribution and technical discovery story. Exim, Ubuntu, and CVE records corroborate the vulnerability, affected product, fix, and critical severity, but the independent records do not themselves describe XBOW's autonomous workflow.

Summary

XBOW’s Dead.Letter write-up describes CVE-2026-45185 as a critical unauthenticated Exim remote-code-execution vulnerability in the GnuTLS BDAT path. Public downstream records identify Exim as affected and point to Exim security advisory material and fixes.

Attribution

This is labeled self-reported because XBOW provides the AI discovery narrative. The vulnerability itself is not only self-reported: Exim, Ubuntu, and CVE records corroborate the public security issue and remediation trail.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.