Low severity3.7NVD Advisory· Published Apr 30, 2026· Updated May 1, 2026
CVE-2026-40686
CVE-2026-40686
Description
In Exim before 4.99.2, when utf8 operators are enabled, there is an out-of-bounds read if large UTF-8 trailing characters are present (malformed UTF-8 header data). Information might be divulged within an error message produced during handling of an unrelated e-mail message.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- code.exim.org/exim/exim/commit/f2570bde16fb4d4a1242ff363a4c4eecf6372efcnvdPatch
- exim.org/static/doc/security/cve-2026-04.1/CVE2026-40686.assessmentnvdVendor Advisory
- www.openwall.com/lists/oss-security/2026/04/30/21nvdMailing ListThird Party Advisory
- exim.org/static/doc/security/CVE-2026-40686.txtnvdBroken Link
News mentions
1- ⚡ Weekly Recap: AI-Powered Phishing, Android Spying Tool, Linux Exploit, GitHub RCE & MoreThe Hacker News · May 4, 2026