CVE-2026-66141
Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.
CVSS
7.4
Alto
EPSS
0.1%
p1
KEV
—
Exploit Today
0
0-100
Publicado: 24 jul 2026 · Última mod.: 30 jul 2026 · CWE-829
0.1%EPSS · 30 días0.1%
2026-07-242026-07-29
Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-659088.6 ALT2.7%
——1In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open7dCVE-2026-648117.8 ALT2.7%
——1In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration3dCVE-2026-648098.4 ALT3.8%
——1In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter3dCVE-2026-648088.4 ALT3.8%
——1In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling3dCVE-2026-648077.8 ALT2.7%
——1In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration3dCVE-2026-648068.4 ALT3.8%
——1In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter3d