logo

Multiple Exim Mail Server Flaws Allow Crashes via Malicious DNS Data

ID: 8a078e50-9e9f-5a6e-bd83-f5834949606a

STIX ID: report--8a078e50-9e9f-5a6e-bd83-f5834949606a

Feed Name: Cyber Press

Threat Score
70/100

Date Published: 2026-05-01

Date Updated: 2026-05-01

Author: AnuPriya

...
...

Exim released version 4.99.2 to patch four security vulnerabilities (CVE-2026-40684–40687) that can lead to denial-of-service, heap memory corruption, or potential data leakage via malformed DNS responses, corrupted JSON headers, oversized UTF-8 characters, and SPA authentication handling; administrators are urged to update immediately as older releases are no longer maintained.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.