二本松哲也[verified]@t_nihonmatsuPatch
The post alerts that Exim instances below certain versions are vulnerable to CVE-2026-40685 and CVE-2026-48840, recommending prompt update to Exim 4.99.4 or later and configuration review.
DMNTR Network Solutions 👻 AS204773[verified]@weareDMNTRsPatch
cPanel released proactive patches for EasyApache 4 and Exim, addressing multiple CVEs including high‑score vulnerabilities CVE‑2026‑23918 and CVE‑2026‑40685.
二本松哲也[verified]@t_nihonmatsuPatch
The post stresses the importance of updating Exim to version 4.99.4+ to mitigate CVE-2026-40685 and CVE-2026-48840, noting that actual risk hinges on configuration settings.
Open Source Security mailing list@oss_securityPatch
The notice announces that Exim 4.99.2 addresses several CVEs, providing a patch update but no exploit details or evidence of active exploitation.
ねこさん⚡(ΦωΦ)@catnap707Disclosure
The article announces that Exim is affected by two critical CVEs (CVE-2026-40685, 40687) with high CVSS scores, but provides no PoC, exploit, or patch information.
CVE@CVEnewDisclosure
The excerpt describes an out‑of‑bounds heap write vulnerability in Exim versions before 4.99.2 that occurs when malformed JSON is parsed in an untrusted header, and it links to the official CVE record.
Samet Geranaz@sametgeranazDisclosure
cPanel has announced new CVEs affecting Exim versions prior to 4.99.2, urging users to update immediately.
Vulmon Vulnerability Feed@VulmonFeedsGeneral
The post references CVE-2026-40685, noting it is an out-of-bounds heap write vulnerability in Exim before 4.99.2 that occurs during JSON lookup processing. No PoC, exploit code, active exploitation, or patch information is provided.