FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Fetchmail -- NTLM potential remote code execution

Affected packages
5.0.8 <= fetchmail < 6.6.7

Details

VuXML ID 15e880b4-b9ed-11f1-b17e-3c7c3fba4204
Discovery 2026-06-27
Entry 2026-09-26

Fetchmail reports:

[CVE-2026-94184]: Fetchmail's NTLM authentication client can in some cases be susceptible to a remote code execution from a malicious server when fetchmail is configured with the NTLM feature enabled, depending on build details. fetchmail 6.6.7 release candidates, 6.6.7 and subsequent releases are unaffected.

References

CVE Name CVE-2026-94184
URL https://nvd.nist.gov/vuln/detail/cve-2026-94184
URL https://www.fetchmail.info/fetchmail-SA-2026-01.txt