CVE-2026-40687Disclosure(exim / exim)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch exim exim systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from uninitialized heap memory.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-909

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • exim

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 3 mentions (2026-04-30); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
exim

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-04-30: 3Mentions · 2026-05-05: 1Mentions · 2026-05-12: 1Patch / Workaround · 2026-04-30: 1Patch / Workaround · 2026-05-05: 1Technical Details · 2026-04-30: 3Technical Details · 2026-05-05: 1Technical Details · 2026-05-12: 104-3005-0505-12
Signal classification2 categories
Disclosure
360.0%
Patch
240.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-303
Disclosure2Patch1
2026-05-051
Patch1
2026-05-121
Disclosure1
Full discourse5 posts
  • Open Source Security mailing list@oss_security
    Patch

    Exim 4.99.2 fixes https://www.openwall.com/lists/oss-security/2026/04/30/21 CVE-2026-40684: Crash with malicious DNS data when using musl libc CVE-2026-40685: OOB read/write on corrupt JSON in header CVE-2026-40686: OOB read with large UTF8 trailing characters CVE-2026-40687: OOB read/write with SPA authenticator

    Post summary

    The post announces that Exim 4.99.2 includes fixes for several CVEs, offering concise technical details but no exploit or PoC references.

    02080453
    4.7K followersView on X
  • ねこさん⚡(ΦωΦ)@catnap707
    Disclosure

    「Exim」に複数脆弱性 - 「クリティカル」との評価も:Security NEXT https://www.security-next.com/184302 "米国立標準技術研究所(NIST)による脆弱性データベース「NVD」において共通脆弱性評価システム「CVSSv3.1」のベーススコアを見ると、「CVE-2026-40685」は「9.8」、「CVE-2026-40687」は「9.1」と評価"

    Post summary

    The text announces critical vulnerabilities in Exim, providing only their CVSS base scores without any PoC, exploit, or patch details.

    10011279
    3.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40687 In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection in… https://www.cve.org/CVERecord?id=CVE-2026-40687

    Post summary

    The post references CVE‑2026‑40687 affecting Exim (v <4.99.2) and describes an out‑of‑bounds write that can crash connections, but provides no PoC, exploit, patch, or active exploitation evidence.

    00010152
    57.4K followersView on X
  • Samet Geranaz@sametgeranaz
    Patch

    cPanel biraz önce yeni bir güvenlik zaafiyeti bildirdi. Exim'de, 4.99.2 öncesi sürümleri etkileyen güvenlik açıkları var.  Exim CVE-2026-40684, CVE-2026-40685, CVE-2026-40686 ve CVE-2026-40687. Acilen cPanel güncellemesi yapın! #cpanel #hack #security

    Post summary

    cPanel disclosed new Exim CVEs (CVE-2026-40684 to CVE-2026-40687) affecting Exim versions prior to 4.99.2 and urges users to apply patches immediately.

    0000078
    465 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-40687 In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection in… https://www.cve.org/CVERecord?id=CVE-2026-40687 ----- Traducción: CVE-2026-40687 En … http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-40687 as a vulnerability in Exim before 4.99.2 involving an out-of-bounds write through the SPA authentication driver, linking to the official CVE record for further details.

    0000014
    75 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appeximexim---

Explore more