Multiple Exim Mail Server Vulnerabilities Could Trigger Crashes via Malicious DNS Data
ID: 8794d039-1c0f-5a59-808e-375253c7ca05
STIX ID: report--8794d039-1c0f-5a59-808e-375253c7ca05
Feed Name: GBHackers
Exim 4.99.2 has been released to remediate four vulnerabilities (CVE-2026-40684, CVE-2026-40685, CVE-2026-40686, CVE-2026-40687) that could allow denial-of-service, heap corruption, and potential memory/data leakage via malicious DNS PTR records, corrupt JSON headers, oversized UTF-8 sequences, and flaws in the SPA authentication driver. Administrators are advised to apply the update immediately because older Exim versions are no longer maintained and the patched source and secure tags are available.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
