Back to Security Advisories

Exim CVE-2026-40684, CVE-2026-40685, CVE-2026-40686, and CVE-2026-40687

Several security vulnerabilities were reported in Exim, impacting versions prior to 4.99.2:

High
cPanel

Default Update CMD

sudo /scripts/upcp --force

Situation

Several security vulnerabilities were reported in Exim, impacting versions prior to 4.99.2:

Impact

An updated Exim package has already been released and is available in the following cPanel versions:

  • 136.0.7
  • 134.0.23
  • 118.0.64
  • 110.0.112

This can be seen in the cPanel & WHM Change Logs:

  • Fixed CPANEL-53011: Update cpanel-exim to 4.99.2 Fixes: CVE-2026-40684, CVE-2026-40685, CVE-2026-40686, and CVE-2026-40687.

The cPanel & WHM Change Logs can be found via the following URL:

cPanel & WHM Change Log

Call to Action

Please update cPanel & WHM to one of the above patched build versions.

How to Apply the Fix

Update the affected packages on your server to the patched release, then restart the relevant services.

sudo /scripts/upcp --force

Check your system for vulnerabilities

Select your product and operating system to see the exact fix commands that apply to you.

Check Your System