Back to Security Advisories

Security: CVE-2026-45185 (Dead.Letter)

The vulnerability, tracked as CVE-2026-45185, aka Dead.Letter, has been described as a use-after-free vulnerability in Exim's binary data transmission (BDAT) message body parsing when a TLS connection is handled by GnuTLS.

Critical 9.8 CVSS
cPanel

Default Update CMD

sudo /scripts/upcp --force

What this means under a SharedLicense license

Your SharedLicense license itself is not affected — this is a vulnerability in cPanel software, not in licensing. Licenses continue to work during and after the update; there is no need to re-issue or re-activate anything. If you resell cPanel under your own brand, patch client servers too — unpatched installs put your reputation at risk, not your license.

Situation

The vulnerability, tracked as CVE-2026-45185, aka Dead.Letter, has been described as a use-after-free vulnerability in Exim’s binary data transmission (BDAT) message body parsing when a TLS connection is handled by GnuTLS.

This issue affects Exim: 4.97+

Impact

None on your cPanel server, as we do not explicitly set USE_GNUTLS when building our version of Exim. Our version has a dependency on OpenSSL and not GnuTLS.

Call to Action

None at this time, as cPanel is not affected by this GnuTLS vulnerability.

Frequently Asked Questions

What is CVE-2026-45185?
Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection. This can lead to heap corruption. An unauthenticated network attacker exploiting this vulnerability could execute arbitrary code.
Is CVE-2026-45185 being exploited in the wild?
No confirmed exploitation is recorded. The EPSS model estimates a 1.23% probability of exploitation within the next 30 days — patch on your normal schedule.
How do I fix CVE-2026-45185?
Update cPanel to the patched release.Then confirm the running version matches the patched release listed above.

Check your system for vulnerabilities

Select your product and operating system to see the exact fix commands that apply to you.

Check Your System