All Topics
All Topics
Technology
Technology
Design
Design
Programming
Programming
Science
Science
News
News
Gaming
Gaming
Entertainment
Entertainment
Business
Business
Finance
Finance
Sports
Sports
Health
Health
Food
Food
Travel
Travel
Art
Art
Music
Music
Books
Books
Education
Education
Politics
Politics
Personal
Personal
No algorithm. No AI slop. No ads. Just RSS. Pro-human. Indie writers. Real journalism. Open web. Chronological. Hand toasted.

CVE-2026-45185 (Dead.Letter): Unauthenticated RCE in Exim Discovered by XBOW

By

FedericoKirschbaumAndresLuksenberg

19d ago· 47 min readenInsight

Summary

XBOW discovered CVE-2026-45185, a critical unauthenticated remote code execution vulnerability in Exim mail server. The article details the discovery process, technical exploitation, and how XBOW used the disclosure window to test both human-led and autonomous exploit development approaches. It's presented as a narrative blending technical vulnerability research with a story-like account of the discovery journey.

Key quotes

· 3 pulled
What follows is, before anything else, a story. One of those old, well-worn ones. A story of encounters and misencounters, of broken hearts and quiet betrayals, of loves once thought to be forever turning out to be something else entirely.
These pages are the by-product of the early days of testing a product we are building. A product focused on finding and detecting vulnerabilities in native code.
So what you are about to read is two things at once. It is the technical account of a vulnerability discovery and exploitation journey.
Snippet from the RSS feed
XBOW discovered CVE-2026-45185, a critical unauthenticated RCE in Exim, and used the disclosure window to test how far human and autonomous exploit development could go.

You might also wanna read