CyberMax
Home › Exploited CVEs

Exim known exploited vulnerabilities

CISA KEV catalog 2026.09.25 (1,726 CVEs) with FIRST EPSS scores from 2026-09-27.

CISA lists 5 Exim CVEs as exploited in the wild. 0 were added in the last 12 months (latest 2022-03-25), and 1 are known to be used in ransomware campaigns.

Exim CVEs added to CISA KEV per year
2021: 1202112022: 420224

Year = when CISA added the CVE to the catalog (KEV started in November 2021).

Patch first: highest EPSS right now

EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.

Most affected Exim products

Exim (3), Exim Internet Mailer (1), Mail Transfer Agent (MTA) (1).

All Exim CVEs in KEV

CVEProductFlawAddedFederal dueEPSSRansomware
CVE-2010-4345EximPrivilege Escalation2022-03-252022-04-1518.0%–
CVE-2010-4344EximHeap-Based Buffer Overflow2022-03-252022-04-1571.7%–
CVE-2019-16928Exim Internet MailerOut-of-bounds Write2022-03-032022-03-1741.6%–
CVE-2019-10149Mail Transfer Agent (MTA)Mail Transfer Agent (MTA) Improper Input Validation2022-01-102022-07-10100.0%–
CVE-2018-6789EximBuffer Overflow2021-11-032022-05-0382.1%Yes
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

Read next: Which CVEs to patch first this week · All vendors