While ZDI reported the vulnerability to the Exim team in June 2022 and resent info on the flaw at the vendor’s request in May 2023, the developers failed to provide an update on their patch progress.
Yikes. Sitting on a critical RCE in internet exposed server software for a year. That’s a great way to destroy trust in a project.
Immutable/offline backups. If you backup to local physical media (HDD/tape), physically disconnect/eject it and store it somewhere safe. If you back up to cloud storage (S3, etc), many of them have immutability options. If configured properly nobody (not even you) can delete or modify the backups (within the specified time period).