logo

Multiple Exim Mail Server Vulnerabilities Could Trigger Crashes via Malicious DNS Data

ID: 8794d039-1c0f-5a59-808e-375253c7ca05

STIX ID: report--8794d039-1c0f-5a59-808e-375253c7ca05

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-05-01

Date Updated: 2026-05-01

Author: Divya

...
...

Exim 4.99.2 has been released to remediate four vulnerabilities (CVE-2026-40684, CVE-2026-40685, CVE-2026-40686, CVE-2026-40687) that could allow denial-of-service, heap corruption, and potential memory/data leakage via malicious DNS PTR records, corrupt JSON headers, oversized UTF-8 sequences, and flaws in the SPA authentication driver. Administrators are advised to apply the update immediately because older Exim versions are no longer maintained and the patched source and secure tags are available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.