CVE-2026-66141
Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.
CVSS
7.4
High
EPSS
0.1%
p1
KEV
—
Exploit Today
0
0-100
Published: Jul 24, 2026 · Last modified: Jul 30, 2026 · CWE-829
0.1%EPSS · 30 days0.1%
2026-07-242026-07-29
Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-659088.6 HIG2.7%
——1In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open7dCVE-2026-648117.8 HIG2.7%
——1In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration2dCVE-2026-648098.4 HIG3.8%
——1In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter2dCVE-2026-648088.4 HIG3.8%
——1In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling2dCVE-2026-648077.8 HIG2.7%
——1In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration2dCVE-2026-648068.4 HIG3.8%
——1In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter2d