CVE-2026-40685Disclosure(exim / exim)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch exim exim systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrusted header, because of an incorrect implementation of \ skipping.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-684CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • exim

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 5d ago at 4 mentions (2026-04-30); latest day: 1
  • 9 total mentions across 6 days

Affected systems

Vendors
Products
exim

Deep dive

Activity timeline9 mentions / 6d
01234Mentions · 2026-04-30: 4Mentions · 2026-05-05: 1Mentions · 2026-05-06: 1Mentions · 2026-05-12: 1Mentions · 2026-07-01: 1Mentions · 2026-07-08: 1Patch / Workaround · 2026-04-30: 1Patch / Workaround · 2026-05-05: 1Patch / Workaround · 2026-05-06: 1Patch / Workaround · 2026-07-01: 1Patch / Workaround · 2026-07-08: 1Technical Details · 2026-04-30: 3Technical Details · 2026-05-06: 1Technical Details · 2026-05-12: 1Technical Details · 2026-07-01: 1Technical Details · 2026-07-08: 104-3005-0505-0605-1207-0107-08
Signal classification3 categories
Disclosure
444.4%
Patch
444.4%
General
111.1%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-304
Disclosure2General1Patch1
2026-05-051
Disclosure1
2026-05-061
Patch1
2026-05-121
Disclosure1
2026-07-011
Patch1
2026-07-081
Patch1
Full discourse9 posts
  • 二本松哲也@t_nihonmatsu
    Patch

    Shodanで確認すると、日本国内でも Exim を外部公開しているホストが多数確認できます。 メールサーバはインターネット境界に置かれることが多く、脆弱性を放置すると、不正アクセス、情報漏えい、踏み台化、メール配送基盤の悪用につながる可能性があります。 CVE-2026-40685 は Exim 4.99.2 未満、 CVE-2026-48840 は条件付きで 4.88〜4.99.3 が影響対象となるため、古い Exim を公開している環境は早急な確認が必要です。 対応としては、まず以下を確認してください。 ・Exim のバージョン確認 ・Exim 4.99.4 以上への更新 ・JSON lookup の利用有無 ・untrusted header を JSON operator で処理していないか ・SUPPORT_PROXY / hosts_proxy の設定有無 ・不要な外部公開や広すぎるアクセス許可の見直し CVSS の点数だけでなく、自組織の構成で攻撃到達性があるかを確認することが重要です。 ただし、MTA は外部公開されやすい重要な境界システムです。該当する可能性がある場合は、至急対応を推奨します。

    Post summary

    The post alerts that Exim instances below certain versions are vulnerable to CVE-2026-40685 and CVE-2026-48840, recommending prompt update to Exim 4.99.4 or later and configuration review.

    11002841.6K
    17.9K followersView on X
  • DMNTR Network Solutions 👻 AS204773@weareDMNTRs
    Patch

    cPanel & WHM — parches para EasyApache 4 (Apache) y Exim cPanel saca parches "proactivos" (sin exploits activos conocidos, dicen). Lo interesante: - EasyApache 4 → 11 CVEs en Apache, destaca CVE-2026-23918 (mod_http2, CVSS 8.8). mod_http2 no viene activo por defecto, pero medio mundo lo activa. - Exim 4.99.2 → 4 CVEs, y aquí el plato fuerte: CVE-2026-40685, CVSS 9.8. Crítica de manual en uno de los MTAs más extendidos. Si gestionas tu infra: a actualizar. Si te la gestiona el proveedor: confía, pero verifica.

    Post summary

    cPanel released proactive patches for EasyApache 4 and Exim, addressing multiple CVEs including high‑score vulnerabilities CVE‑2026‑23918 and CVE‑2026‑40685.

    1001023.2K
    25.8K followersView on X
  • Open Source Security mailing list@oss_security
    Patch

    Exim 4.99.2 fixes https://www.openwall.com/lists/oss-security/2026/04/30/21 CVE-2026-40684: Crash with malicious DNS data when using musl libc CVE-2026-40685: OOB read/write on corrupt JSON in header CVE-2026-40686: OOB read with large UTF8 trailing characters CVE-2026-40687: OOB read/write with SPA authenticator

    Post summary

    The notice announces that Exim 4.99.2 addresses several CVEs, providing a patch update but no exploit details or evidence of active exploitation.

    02080453
    4.7K followersView on X
  • ねこさん⚡(ΦωΦ)@catnap707
    Disclosure

    「Exim」に複数脆弱性 - 「クリティカル」との評価も:Security NEXT https://www.security-next.com/184302 "米国立標準技術研究所(NIST)による脆弱性データベース「NVD」において共通脆弱性評価システム「CVSSv3.1」のベーススコアを見ると、「CVE-2026-40685」は「9.8」、「CVE-2026-40687」は「9.1」と評価"

    Post summary

    The article announces that Exim is affected by two critical CVEs (CVE-2026-40685, 40687) with high CVSS scores, but provides no PoC, exploit, or patch information.

    10011279
    3.5K followersView on X
  • 二本松哲也@t_nihonmatsu
    Patch

    ありがとうございます。 おっしゃる通り、まずは Exim 4.99.4 以上への更新が最優先ですね。 CVE-2026-40685 は NVD では 9.8 Critical と評価されていますが、実際のリスクは JSON lookup の利用有無や、untrusted header を JSON operator で処理しているかに依存します。 そのため深刻だが、構成確認が重要という整理が実務的だと思います。 あわせて、CVE-2026-48840 のように PROXY protocol / hosts_proxy の設定に依存する脆弱性もあるため、単にバージョンだけでなく、Exim の有効機能と到達経路を確認することが大切ですね。

    Post summary

    The post stresses the importance of updating Exim to version 4.99.4+ to mitigate CVE-2026-40685 and CVE-2026-48840, noting that actual risk hinges on configuration settings.

    0000186
    15.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40685 In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrusted header, becau… https://www.cve.org/CVERecord?id=CVE-2026-40685

    Post summary

    The excerpt describes an out‑of‑bounds heap write vulnerability in Exim versions before 4.99.2 that occurs when malformed JSON is parsed in an untrusted header, and it links to the official CVE record.

    00010141
    57.4K followersView on X
  • Samet Geranaz@sametgeranaz
    Disclosure

    cPanel biraz önce yeni bir güvenlik zaafiyeti bildirdi. Exim'de, 4.99.2 öncesi sürümleri etkileyen güvenlik açıkları var.  Exim CVE-2026-40684, CVE-2026-40685, CVE-2026-40686 ve CVE-2026-40687. Acilen cPanel güncellemesi yapın! #cpanel #hack #security

    Post summary

    cPanel has announced new CVEs affecting Exim versions prior to 4.99.2, urging users to update immediately.

    0000078
    465 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-40685 Out-of-Bounds Heap Write in Exim Before 4.99.2 JSON Lookup https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40685

    Post summary

    The post references CVE-2026-40685, noting it is an out-of-bounds heap write vulnerability in Exim before 4.99.2 that occurs during JSON lookup processing. No PoC, exploit code, active exploitation, or patch information is provided.

    0000042
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-40685 In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrusted header, becau… https://www.cve.org/CVERecord?id=CVE-2026-40685 ----- Traducción: CVE-2026-40685 En … http://infoflow.cloud`

    Post summary

    The text announces CVE-2026-40685, describing an out‑of‑bounds heap write in Exim when JSON lookup processes malformed JSON, but offers no PoC, exploit, or patch details.

    0000019
    75 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appeximexim---

Explore more