CVE-2026-40684Disclosure(exim / exim)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch exim exim systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a dn_expand oddity in octal printing.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-684

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • exim

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • Peaked 3d ago at 3 mentions (2026-04-30); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
exim

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-04-30: 3Mentions · 2026-05-01: 1Mentions · 2026-05-02: 1Mentions · 2026-05-05: 1Patch / Workaround · 2026-04-30: 1Patch / Workaround · 2026-05-02: 1Patch / Workaround · 2026-05-05: 1Technical Details · 2026-04-30: 3Technical Details · 2026-05-01: 1Technical Details · 2026-05-02: 1Technical Details · 2026-05-05: 104-3005-0105-0205-05
Signal classification2 categories
Disclosure
350.0%
Patch
350.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-303
Disclosure2Patch1
2026-05-011
Disclosure1
2026-05-021
Patch1
2026-05-051
Patch1
Full discourse6 posts
  • Open Source Security mailing list@oss_security
    Patch

    Exim 4.99.2 fixes https://www.openwall.com/lists/oss-security/2026/04/30/21 CVE-2026-40684: Crash with malicious DNS data when using musl libc CVE-2026-40685: OOB read/write on corrupt JSON in header CVE-2026-40686: OOB read with large UTF8 trailing characters CVE-2026-40687: OOB read/write with SPA authenticator

    Post summary

    Exim 4.99.2 releases fixes for CVE-2026-40684 through CVE-2026-40687, addressing crashes and out‑of‑bounds read/write issues involving malicious DNS data, corrupt JSON headers, large UTF‑8 trailing characters, and SPA authentication data.

    02080453
    4.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40684 In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This i… https://www.cve.org/CVERecord?id=CVE-2026-40684

    Post summary

    The text announces CVE-2026-40684, a crash vulnerability in Exim before 4.99.2 on musl libc systems triggered by malformed DNS PTR records.

    00010142
    57.4K followersView on X
  • Samet Geranaz@sametgeranaz
    Patch

    cPanel biraz önce yeni bir güvenlik zaafiyeti bildirdi. Exim'de, 4.99.2 öncesi sürümleri etkileyen güvenlik açıkları var.  Exim CVE-2026-40684, CVE-2026-40685, CVE-2026-40686 ve CVE-2026-40687. Acilen cPanel güncellemesi yapın! #cpanel #hack #security

    Post summary

    cPanel has announced four new CVEs affecting Exim versions older than 4.99.2 and urges users to apply patches immediately to mitigate potential exploitation.

    0000078
    465 followersView on X
  • DNSAudit.io@dnsaudit
    Patch

    🚨 Malformed DNS Data Can Crash Exim Mail Servers https://cybersecuritynews.com/exim-mail-server-vulnerabilities/ Exim has patched four new flaws in version 4.99.2, but the DNS-related bug is the one that caught our attention. CVE-2026-40684 can crash a connection instance when Exim processes malformed PTR records on systems using the musl C library. In plain terms, bad DNS data can turn into a mail server crash. For exposed mail infrastructure, that is not something to leave sitting around. If you run Exim, check your version and update to 4.99.2. #DNS #DNSSecurity #Exim #CyberSecurity #InfoSec

    Post summary

    Exim mail servers are vulnerable to CVE-2026-40684, which can cause crashes when processing malformed PTR DNS records; the issue is fixed in version 4.99.2.

    0000043
    14 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40684 Denial of Service in Exim Before 4.99.2 via Malformed DNS PTR Records https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40684

    Post summary

    The text announces CVE-2026-40684, detailing a Denial of Service in Exim before 4.99.2 triggered by malformed DNS PTR records, but offers no proof of concept, exploit code, or patch information.

    0000038
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-40684 In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This i… https://www.cve.org/CVERecord?id=CVE-2026-40684 ----- Traducción: CVE-2026-40684 En … http://infoflow.cloud`

    Post summary

    CVE-2026-40684 details a denial‑of‑service vulnerability in Exim 4.99.x on musl libc systems, caused by malformed DNS PTR records, with no known exploit or patch provided in this text.

    0000019
    75 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appeximexim---

Explore more