Open Source Security mailing list@oss_securityPatch
Exim 4.99.2 released a patch that addresses four CVEs involving crashes and out‑of‑bounds memory issues.
CVE@CVEnewDisclosure
The text announces CVE‑2026‑40686 in Exim, outlining an out‑of‑bounds read triggered by malformed UTF‑8 header data in versions prior to 4.99.2; no PoC, exploit, or patch is mentioned.
Samet Geranaz@sametgeranazPatch
cPanel reports multiple CVEs (CVE‑2026‑40684–40687) affecting Exim versions prior to 4.99.2 and urges users to apply updates.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The text refers to CVE‑2026‑40686, describing an out‑of‑bounds read vulnerability in Exim versions before 4.99.2 when UTF‑8 operators are enabled, but it does not provide PoC, exploit code, active exploitation evidence, or a patch.
Infoflowcloud@infoflowcloudDisclosure
This post announces CVE-2026-40686, noting that Exim versions before 4.99.2 with UTF‑8 operators enabled suffer an out‑of‑bounds read when large malformed UTF‑8 trailing characters are present.