Review reviewHigh
CVE-2026-66141
Exim
Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.
- CVSS
- 7.4
- EPSS
- - - percentile
- CISA KEV
- Not listed
- Published
- 2026.07.24
Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.
The CVSS severity warrants an early asset and exposure review.
Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.
Confirm exposure before applying a vendor-supported change.
Confirm that Exim and an affected version are present.
Combine exploitation signals with asset exposure and business criticality.
Follow the vendor advisory or supported update path and preserve rollback options.
Recheck the version, service health, access paths, and relevant logs.