Signal

Critical vulnerabilities disclosed in Exim mail server versions 4.97 to 4.99.2

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-05-12 16:44 UTCUpdated 2026-05-13 14:58 UTC
rss
cvesecurity_advisoriespatchesincident_response
Trend in the last 24h
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (2 domains)domains are deduped. counts indicate coverage, not truth.
2 top sources shown
Exim security advisory (AV26-460)
Canadian Centre for Cyber Security - Alerts · News · cyber.gc.ca · 2026-05-13 14:58 UTC
exim4: CVSS (Max): None
AusCERT - Bulletins · News · portal.auscert.org.au · 2026-05-13 04:01 UTC
limited source diversity in top sources
Overview

On May 12, 2026, Exim published a security advisory addressing multiple critical vulnerabilities affecting versions 4.97 to 4.99.2 of its mail transport agent. The highest severity CVE (CVE-2026-40685) scores 9.8 on the CVSS scale, indicating remote code execution risks without user interaction.

Entities
EximDebianExim4Salvatore BonaccorsoThorsten Alteholz
Score total
1.13
Momentum 24h
3
Posts
3
Origins
2
Source types
1
Duplicate ratio
0%
Why now
  • Exim advisory and Debian patches were released on May 12-13, 2026.
  • High CVSS scores indicate urgent security risk.
  • Multiple national cybersecurity organizations have issued alerts urging immediate action.
Why it matters
  • Exim is a widely deployed mail server; vulnerabilities risk widespread exploitation.
  • Remote code execution flaws can lead to full system compromise.
  • Timely patching is critical to prevent attacks leveraging these vulnerabilities.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: high
Recurring claims
  • Exim versions 4.97 to 4.99.2 contain critical vulnerabilities allowing remote code execution.
  • Debian has released security patches for Exim vulnerabilities affecting Debian GNU/Linux and Debian 11 Bullseye.
How sources frame it
  • Canadian Centre For Cyber Security: neutral
All evidence
All evidence
Exim security advisory (AV26-460)
Canadian Centre for Cyber Security - Alerts · cyber.gc.ca · 2026-05-13 14:58 UTC
exim4: CVSS (Max): None
AusCERT - Bulletins · portal.auscert.org.au · 2026-05-13 04:01 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 2Origin domains: 2Duplicates: -
Showing 2 / 0
Top publishers (this list)
  • Canadian Centre for Cyber Security - Alerts (1)
  • AusCERT - Bulletins (1)
Top origin domains (this list)
  • cyber.gc.ca (1)
  • portal.auscert.org.au (1)