{"id":12578,"date":"2026-05-03T10:03:35","date_gmt":"2026-05-03T10:03:35","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/05\/03\/multiple-exim-mail-server-vulnerabilities-leads-to-crash-with-malicious-dns-data\/"},"modified":"2026-05-03T10:03:35","modified_gmt":"2026-05-03T10:03:35","slug":"multiple-exim-mail-server-vulnerabilities-leads-to-crash-with-malicious-dns-data","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/05\/03\/multiple-exim-mail-server-vulnerabilities-leads-to-crash-with-malicious-dns-data\/","title":{"rendered":"Multiple Exim Mail Server Vulnerabilities Leads to Crash with Malicious DNS data"},"content":{"rendered":"<p>    Multiple Exim Mail Server Vulnerabilities Leads to Crash with Malicious DNS data<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>The Exim development team has released version 4.99.2 to address four newly discovered security vulnerabilities affecting their mail server software.<\/p>\n<p>These flaws allow attackers to potentially crash servers, corrupt memory, or leak sensitive information.<\/p>\n<p>Because Exim is one of the most widely used message transfer agents on the internet, system administrators need to apply this update immediately to secure their email infrastructure.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-breakdown-of-the-discovered-vulnerabilities\"><strong>Breakdown of the Discovered Vulnerabilities<\/strong><\/h2>\n<p>The latest security update patches four distinct Common Vulnerabilities and Exposures (CVEs) that affect how the server processes external inputs.<\/p>\n<ul class=\"wp-block-list\">\n<li>\n<strong>CVE-2026-40684<\/strong> causes a crash with <a href=\"https:\/\/cybersecuritynews.com\/russian-hackers-exploiting-routers\/\" target=\"_blank\" rel=\"noreferrer noopener\">malicious DNS data<\/a> malformed PTR records trigger an octal printing error on systems using the musl C library, resulting in a complete crash of the connection instance.\n<\/li>\n<li>\n<span style=\"box-sizing: border-box; margin: 0px; padding: 0px;\"><strong>CVE-2026-40685<\/strong>\u00a0triggers out-of-bounds read and write operations on<a href=\"https:\/\/cybersecuritynews.com\/mad-cat-meow-attack-tool\/\" target=\"_blank\" rel=\"noopener\">\u00a0corrupted JSON configurations<\/a>\u00a0that use JSON operators on invalid external input, which can directly lead to heap corruption.<\/span>\n<\/li>\n<li>\n<strong>CVE-2026-40686<\/strong> exposes out-of-bounds read issues via large UTF-8 trailing characters; processing malformed headers might leak data if error messages are required for subsequent emails in the same connection.\n<\/li>\n<li>\n<strong>CVE-2026-40687<\/strong> creates out-of-bounds vulnerabilities in the SPA authenticator; connecting to a compromised external SPA or NTLM service can cause the instance to crash or<a href=\"https:\/\/cybersecuritynews.com\/critical-vulnerabilities-in-delphi-code\/\" target=\"_blank\" rel=\"noreferrer noopener\"> leak heap memory<\/a>.<\/li>\n<\/ul>\n<p>Mail servers act as the central communication backbone for modern organizations, making them highly attractive targets for threat actors.<\/p>\n<p>When attackers exploit <a href=\"https:\/\/cybersecuritynews.com\/out-of-bounds-read-and-write\/\" target=\"_blank\" rel=\"noreferrer noopener\">out-of-bounds read and write vulnerabilities<\/a>, they manipulate how a program allocates its memory space.<\/p>\n<p>This allows malicious users to extract sensitive data they shouldn\u2019t be able to access or to overwrite data, disrupting normal server operations.<\/p>\n<p>The DNS-related crash specifically highlights how a simple malformed record can cause a <a href=\"https:\/\/cybersecuritynews.com\/nvidia-merlin-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">denial-of-service condition<\/a> for systems that rely on the musl C library.<\/p>\n<p>Threat actors routinely deploy automated scanners to identify unpatched mail servers connected to the internet.<\/p>\n<p>Leaving these endpoints exposed makes them highly vulnerable to automated exploitation and targeted data extraction campaigns.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-mitigation-steps\"><strong>Mitigation Steps<\/strong><\/h2>\n<p>System administrators should prioritize upgrading to Exim 4.99.2 immediately.<\/p>\n<p>The official security release is currently available as a tarball download from the primary Exim FTP site. It can also be pulled directly from the official Exim Git repository.<\/p>\n<p><a href=\"https:\/\/lists.exim.org\/lurker\/message\/20260429.121733.f58d9686.en.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">According to the advisory<\/a>, older versions of Exim are no longer actively maintained, and network defenders should take note.<\/p>\n<p>This means legacy deployments may carry these vulnerabilities permanently unless upgraded to the current branch.<\/p>\n<p>Administrators should also review their email header configurations to ensure proper validation of externally provided JSON and UTF-8 inputs.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/exim-mail-server-vulnerabilities\/\">Multiple Exim Mail Server Vulnerabilities Leads to Crash with Malicious DNS data<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/exim-mail-server-vulnerabilities\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Multiple Exim Mail Server Vulnerabilities Leads to Crash with Malicious DNS data The Exim development team has released version 4.99.2 to address four newly discovered security vulnerabilities affecting their mail server software. These flaws allow attackers to potentially crash servers, corrupt memory, or leak sensitive information. Because Exim is one of the most widely used [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,648],"tags":[130],"class_list":["post-12578","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12578"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=12578"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12578\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=12578"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=12578"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=12578"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}