
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-40687 is an out-of-bounds read/write vulnerability in the SPA (NTLM) authentication driver of Exim mail server. When Exim is configured to use the SPA authentication driver and connects to a hostile or compromised external SPA/NTLM endpoint, an adversarial SPA resource can trigger an out-of-bounds write that crashes the connection instance, or erroneous data processing that exposes uninitialized heap memory contents. All Exim versions before 4.99.2 are affected. The vulnerability was disclosed on April 30, 2026, alongside three other CVEs fixed in the same release. The CVSS v3.1 base score is reported as 9.1 (Critical) by Feedly/NVD, though the GitHub Advisory Database and EUVD assign a more conservative score of 4.8 (Moderate) with higher attack complexity (GitHub Advisory, oss-security).
The root cause is classified as CWE-909 (Missing Initialization of Resource), where the SPA authentication driver fails to properly initialize heap memory before use, and does not adequately validate the bounds of data received from an external SPA/NTLM resource (GitHub Advisory). An attacker controlling or impersonating an SPA/NTLM authentication endpoint can supply a maliciously crafted SPA resource that triggers an out-of-bounds write, crashing the Exim connection instance, or causes erroneous data processing that leaks uninitialized heap memory back to the attacker. Exploitation requires that the target Exim instance is configured to use the SPA authentication driver — this is not a default configuration. The fix is available in commit 68b963b9f75ca27b38e1c0f8c87037990199f505 in the Exim repository (Exim Commit).
Successful exploitation can result in two distinct outcomes: a denial of service by crashing the affected Exim connection instance, or an information disclosure attack that leaks contents of uninitialized heap memory to the adversarial endpoint. Heap memory leakage may expose sensitive data such as credentials, email content fragments, or other in-memory data processed by the mail server. The attack requires no privileges and no user interaction, making it remotely exploitable by any attacker who can position themselves as a hostile SPA/NTLM server relative to the Exim instance (GitHub Advisory, oss-security).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.052% (Feedly) to 0.182% (GitHub Advisory), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. Exploitation is constrained by the requirement that the target Exim instance uses the non-default SPA authentication driver and that the attacker can act as or compromise the SPA/NTLM server endpoint.
/var/log/exim4/mainlog or equivalent, particularly during SPA/NTLM authentication phases; error messages referencing the SPA authenticator or memory access violations.Upgrade Exim to version 4.99.2 or later, which contains the fix for CVE-2026-40687 along with three other CVEs (CVE-2026-40684, CVE-2026-40685, CVE-2026-40686) (oss-security). Packages are available via official distribution channels including Ubuntu (USN-8228-1, USN-8382-1) and Debian (DSA-6265-1), as well as cPanel hosting environments (cPanel Advisory). As an interim workaround if immediate patching is not possible, disable the SPA authentication driver in the Exim configuration if it is not required for mail server operations. Monitor Exim logs for unexpected connection crashes during authentication.
The vulnerability was part of a coordinated disclosure of four Exim CVEs fixed in version 4.99.2, announced to the distros mailing list on April 24, 2026, and publicly disclosed on April 29–30, 2026 (oss-security). Security news outlets including GBHackers, CyberPress, and CyberSecurityNews covered the batch of Exim vulnerabilities, focusing on the potential for crashes via malicious DNS data and memory leaks. A Reddit thread in r/cpanel noted the rapid succession of security updates affecting cPanel environments (cPanel, kernel, and Exim) in a short period. The Exim release announcement notably included a pointed remark thanking "the thousands of unnamed and uncredited authors whose works were ingested into the slopbots" in reference to AI-assisted vulnerability reporting (oss-security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."