CVE-2026-40687: medium-severity vulnerability in Exim
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 4.8epss 0.7%
exploitation probability
0.7%top 50% of all CVEs
observed exploitation
nono source reports it
In short
Exim email server has a flaw in its SPA authentication method that can crash connections or leak sensitive data from memory when processing specially crafted authentication requests.
Technical detail
An out-of-bounds write vulnerability exists in Exim's SPA authentication driver (CWE-909) when processing adversarial SPA resources, enabling denial of service via connection crash or information disclosure through uninitialized heap memory access. Exploitation requires sending a malformed SPA authentication request to an Exim instance configured with SPA driver enabled.
Summary generated and translated by AI from the official description.
In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from uninitialized heap memory.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
Affected products
Exim · EximRelated CVEs — Exim
In the same product, most dangerous first.
CVE-2025-26794HIGHCVE-2025-26794EPSS 77.6%CVE-2023-42114LOWExim NTLM Challenge Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 26.9%CVE-2023-42115CRITICALExim AUTH Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 12.1%CVE-2023-42117HIGHExim Improper Neutralization of Special Elements Remote Code Execution VulnerabilityEPSS 6.8%CVE-2023-42116HIGHExim SMTP Challenge Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 3.8%CVE-2023-42119LOWExim dnsdb Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 1.6%