Exim has released version 4.99.2 as a security update to fix four vulnerabilities in the mail transfer agent, tracked as CVE-2026-40684, CVE-2026-40685, CVE-2026-40686, and CVE-2026-40687. The flaws affect specific configurations and stem from unsafe handling of DNS PTR data, corrupt JSON in headers, malformed UTF-8 in headers, and the SPA authenticator when interacting with a hostile or compromised external SPA/NTLM service. Reported impacts include crashes, heap corruption, out-of-bounds reads and writes, and possible heap data leakage, with older Exim branches potentially affected but no longer actively maintained.
One of the disclosed issues, CVE-2026-40684, can crash an Exim connection on systems using musl libc when malformed DNS PTR record data is processed; the same behavior was not reported on glibc systems. Exim said the bug is linked to an octal-printing oddity in musl libc and noted that the issue was raised with the musl maintainer. The fixes were published through Exim's security advisory process and made available in source tarballs and the project's Git repository under the exim-4.99.2 tag.

See real exploitation activity before you spend the cycle.
6 events from the most recent confirmed update back to the earliest known activity.
Debian published security advisory DSA 6265-1 announcing a security update for exim4 to address the Exim vulnerabilities previously disclosed upstream. This marks downstream distribution remediation for Debian users.
cPanel published a product advisory covering CVE-2026-40684, CVE-2026-40685, CVE-2026-40686, and CVE-2026-40687 affecting Exim. The advisory represents downstream vendor guidance and remediation tracking for cPanel-managed systems.
Solar Designer relayed the Exim 4.99.2 security release and its four associated vulnerabilities to the oss-security mailing list. Follow-up discussion highlighted that CVE-2026-40684 causes crashes on musl libc systems when malformed DNS PTR data is processed, but not on glibc.
The Exim project publicly announced Exim 4.99.2 on the exim-announce list as a security release. This announcement formalized availability of the patched version for users and downstream maintainers.
Exim released version 4.99.2 as a security update to remediate CVE-2026-40684, CVE-2026-40685, CVE-2026-40686, and CVE-2026-40687. The release was made available as source tarballs and in the Exim Git repository under tag exim-4.99.2.
Exim issued security advisory EXIM-Security-2026-04-24 covering four vulnerabilities affecting specific configurations, including issues in DNS PTR handling, JSON header parsing, UTF-8 header processing, and SPA/NTLM authentication. The flaws could cause crashes, out-of-bounds reads or writes, heap corruption, or possible heap data leakage, and older unsupported versions may also be affected.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
7 references tracked. Mallory keeps watching after this page renders.
lists.debian.org
Open sourcesupport.cpanel.net
Open sourcecybersecuritynews.com
Open sourcelists.exim.org
Open sourceseclists.org
Open sourceseclists.org
Open sourceopennet.me
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.