This might have slipped under the radar these past few days, but a 9.8 RCE in Exim (on many, many mail servers) that does not require authentication is bad bad bad.

https://www.zerodayinitiative.com/advisories/ZDI-23-1469/

@briankrebs @mutax it is especially bad since a lot of Debian systems defaulted to exim, and the people running them are probably unaware that it's installed. It should only be listening to localhost, but still.