AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N L N 5.3 .0020 8.5 —
AFFECTED Product Versions Fixed Exim unspecified —
TIMELINE Sep 19 Reserved by mitre Sep 19 Published (CNA: mitre) Sep 24 RESCORED — CVE-2026-94057 (Exim). CVSS 4 → 5.3 (NVD).
Reference page — cumulative record through Saturday, October 3, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N L N 5.3 .0020 8.5 —
AFFECTED Product Versions Fixed Exim unspecified —
TIMELINE Sep 19 Reserved by mitre Sep 19 Published (CNA: mitre) Sep 24 RESCORED — CVE-2026-94057 (Exim). CVSS 4 → 5.3 (NVD).
Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent after a rejection during DATA processing.
| Date | Event | Detail |
|---|---|---|
| September 19, 2026 | Reserved | Reserved by mitre |
| September 19, 2026 | Published | Published (CNA: mitre) |
| September 24, 2026 | RESCORED | RESCORED — CVE-2026-94057 (Exim). CVSS 4 → 5.3 (NVD). |
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
|---|---|---|---|---|
| Exim | Exim | — | — | — |
Authoritative record: CVE-2026-94057 at cve.org
Vendors: exim
Weaknesses: CWE-93
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-94057 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Saturday, October 3, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.