{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/fetchmail/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:fetchmail:fetchmail:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-94184"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["fetchmail"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["fetchmail"],"content_html":"\u003cp\u003eCVE-2026-94184 is a critical vulnerability within the fetchmail utility, specifically occurring when the software is compiled with NTLM authentication support enabled. The issue stems from a stack-based buffer overflow that occurs during the processing of NTLM authentication responses. When a client connects to a malicious or compromised mail server, the server can supply a crafted Type 2 NTLM challenge. As the fetchmail client attempts to build the corresponding NTLM authenticate response, the data is written to a fixed-size stack buffer without adequate bounds checking. This flaw can be exploited to cause a crash (denial of service) or potentially achieve remote code execution depending on the specific memory layout and the presence of stack hardening features on the host system.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows a malicious mail server to terminate the fetchmail process or execute arbitrary code on the system running the client, potentially leading to full system compromise. The vulnerability affects all deployments of fetchmail where NTLM authentication support is compiled in, representing a significant risk to organizations using fetchmail for periodic email retrieval.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize auditing internal and external mail relay infrastructure to identify instances where NTLM authentication is utilized with fetchmail. Review vendor release notes and apply patches to the latest version of fetchmail to remediate the buffer overflow. Given the low-level nature of this memory corruption vulnerability, prioritize patching on systems that retrieve mail from untrusted or external mail providers.\u003c/p\u003e\n","date_modified":"2026-09-21T16:29:32Z","date_published":"2026-09-21T16:29:32Z","id":"https://feed.craftedsignal.io/briefs/2026-09-fetchmail-cve-2026-94184/","summary":"A stack-based buffer overflow in fetchmail's NTLM support allows a malicious mail server to trigger memory corruption and potential remote code execution via a crafted Type 2 challenge.","title":"Stack-based Buffer Overflow in fetchmail NTLM Authentication","url":"https://feed.craftedsignal.io/briefs/2026-09-fetchmail-cve-2026-94184/"}],"language":"en","title":"CraftedSignal Threat Feed - Fetchmail","version":"https://jsonfeed.org/version/1.1"}