Volver a los avisos de seguridad

Exim CVE-2026-40684, CVE-2026-40685, CVE-2026-40686, and CVE-2026-40687

Several security vulnerabilities were reported in Exim, impacting versions prior to 4.99.2:

High 5.9 CVSS
cPanel

CMD de actualización por defecto

yum update exim && systemctl restart exim

Lo que esto significa bajo una licencia de SharedLicense

Your SharedLicense license itself is not affected — this is a vulnerability in cPanel software, not in licensing. Licenses continue to work during and after the update; there is no need to re-issue or re-activate anything. If you resell cPanel under your own brand, patch client servers too — unpatched installs put your reputation at risk, not your license.

Situation

Several security vulnerabilities were reported in Exim, impacting versions prior to 4.99.2:

Impact

An updated Exim package has already been released and is available in the following cPanel versions:

  • 136.0.7
  • 134.0.23
  • 118.0.64
  • 110.0.112

This can be seen in the cPanel & WHM Change Logs:

  • Fixed CPANEL-53011: Update cpanel-exim to 4.99.2 Fixes: CVE-2026-40684, CVE-2026-40685, CVE-2026-40686, and CVE-2026-40687.

The cPanel & WHM Change Logs can be found via the following URL:

cPanel & WHM Change Log

Call to Action

Please update cPanel & WHM to one of the above patched build versions.

Preguntas frecuentes

What is CVE-2026-40684?
In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a dn_expand oddity in octal printing.
Is CVE-2026-40684 being exploited in the wild?
No confirmed exploitation is recorded. The EPSS model estimates a 0.36% probability of exploitation within the next 30 days — patch on your normal schedule.
How do I fix CVE-2026-40684?
Update cPanel to the patched release.Then confirm the running version matches the patched release listed above.
Why does this advisory list several CVEs?
One vendor release fixed multiple vulnerabilities. This advisory covers CVE-2026-40684, CVE-2026-40685, CVE-2026-40686, CVE-2026-40687 — updating to the patched release resolves all of them at once.

Comprueba tu sistema en busca de vulnerabilidades

Selecciona tu producto y sistema operativo para ver los comandos de corrección exactos que se aplican a ti.

Comprueba tu sistema