New Exim BDAT Vulnerability Exposes GnuTLS Builds to Potential Code Execution
2026-05-12T19:24:13Z•58fe73aa1f6556b5b0a4ccd4b34957d872a506f878f20d19a3f1e03e3ca9f1cd
Android banking trojan','TON C2','SOCKS5','Quasar Linux RAT','QuBleeding LlamaCheckmarxDirty FragFilemanager backdoorGnuTLSIvanti EPMMLinux kernelMini Shai-HuludOllamaPyPIRCERubyGemsTeamPCPTrickMoWHMactive exploitationcPaneleximlocal privilege escalationmalicious packagesnpmout-of-bounds readsupply chainuse-after-free
What happened
Multiple high-impact security incidents and active-exploitation vulnerabilities were reported: Exim BDAT use-after-free (CVE-2026-45185, 'Dead.Letter') risks memory corruption and possible code execution in GnuTLS-linked builds; cPanel/WHM flaws (CVE-2026-41940 actively exploited to install a Filemanager backdoor; additional fixes including CVE-2026-29201) and Ivanti EPMM RCE (CVE-2026-6973) are being abused in the wild; Ollama has a critical out-of-bounds read (CVE-2026-7482, CVSS 9.1) enabling remote process memory leakage. Other notable activity includes widespread software supply-chain and
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 58fe73aa1f6556b5b0a4ccd4b34957d872a506f878f20d19a3f1e03e3ca9f1cd
- Enrichment time
- 2026-05-12T19:24:13Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.