CVE-2026-40687 is a memory-safety vulnerability in Exim before version 4.99.2 affecting configurations that use the SPA authentication driver. When Exim communicates with a hostile, compromised, or otherwise adversarial external SPA or NTLM service, malformed authentication data can trigger out-of-bounds memory access in the SPA authenticator. Reported behavior includes out-of-bounds write conditions that can crash the connection-handling instance, as well as erroneous processing that may disclose data from uninitialized heap memory. The issue is therefore both a stability and information disclosure flaw in Exim's authentication handling path.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An Exim SPA authenticator vulnerability that can cause crashes or heap memory disclosure when interacting with a compromised external SPA or NTLM service.
A vulnerability in Exim authentication handling related to SPA (Simple Password Authentication), potentially affecting SPA/NTLM authentication flows.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.