CVE-2026-40686Disclosure(exim / exim)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch exim exim systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In Exim before 4.99.2, when utf8 operators are enabled, there is an out-of-bounds read if large UTF-8 trailing characters are present (malformed UTF-8 header data). Information might be divulged within an error message produced during handling of an unrelated e-mail message.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • exim

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 3 mentions (2026-04-30); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
exim

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-04-30: 3Mentions · 2026-05-01: 1Mentions · 2026-05-05: 1Patch / Workaround · 2026-04-30: 1Patch / Workaround · 2026-05-05: 1Technical Details · 2026-04-30: 3Technical Details · 2026-05-01: 1Technical Details · 2026-05-05: 104-3005-0105-05
Signal classification2 categories
Disclosure
360.0%
Patch
240.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-303
Disclosure2Patch1
2026-05-011
Disclosure1
2026-05-051
Patch1
Full discourse5 posts
  • Open Source Security mailing list@oss_security
    Patch

    Exim 4.99.2 fixes https://www.openwall.com/lists/oss-security/2026/04/30/21 CVE-2026-40684: Crash with malicious DNS data when using musl libc CVE-2026-40685: OOB read/write on corrupt JSON in header CVE-2026-40686: OOB read with large UTF8 trailing characters CVE-2026-40687: OOB read/write with SPA authenticator

    Post summary

    Exim 4.99.2 released a patch that addresses four CVEs involving crashes and out‑of‑bounds memory issues.

    02080453
    4.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40686 In Exim before 4.99.2, when utf8 operators are enabled, there is an out-of-bounds read if large UTF-8 trailing characters are present (malformed UTF-8 header data). I… https://www.cve.org/CVERecord?id=CVE-2026-40686

    Post summary

    The text announces CVE‑2026‑40686 in Exim, outlining an out‑of‑bounds read triggered by malformed UTF‑8 header data in versions prior to 4.99.2; no PoC, exploit, or patch is mentioned.

    00010144
    57.4K followersView on X
  • Samet Geranaz@sametgeranaz
    Patch

    cPanel biraz önce yeni bir güvenlik zaafiyeti bildirdi. Exim'de, 4.99.2 öncesi sürümleri etkileyen güvenlik açıkları var.  Exim CVE-2026-40684, CVE-2026-40685, CVE-2026-40686 ve CVE-2026-40687. Acilen cPanel güncellemesi yapın! #cpanel #hack #security

    Post summary

    cPanel reports multiple CVEs (CVE‑2026‑40684–40687) affecting Exim versions prior to 4.99.2 and urges users to apply updates.

    0000078
    465 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40686 Out-of-Bounds Read in Exim Before 4.99.2 With UTF-8 Operators Enabled https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40686

    Post summary

    The text refers to CVE‑2026‑40686, describing an out‑of‑bounds read vulnerability in Exim versions before 4.99.2 when UTF‑8 operators are enabled, but it does not provide PoC, exploit code, active exploitation evidence, or a patch.

    0000034
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-40686 In Exim before 4.99.2, when utf8 operators are enabled, there is an out-of-bounds read if large UTF-8 trailing characters are present (malformed UTF-8 header data). I… https://www.cve.org/CVERecord?id=CVE-2026-40686 ----- Traducción: CVE-2026-40686 En … http://infoflow.cloud`

    Post summary

    This post announces CVE-2026-40686, noting that Exim versions before 4.99.2 with UTF‑8 operators enabled suffer an out‑of‑bounds read when large malformed UTF‑8 trailing characters are present.

    0000018
    75 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appeximexim---

Explore more