PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-40686 cPanel CVE debrief

cPanel’s advisory groups CVE-2026-40686 with three related Exim issues and says the fix is already available in updated cPanel/WHM builds. The vendor notes that Exim versions prior to 4.99.2 are affected and that upgrading cPanel/WHM to a patched release updates cpanel-exim to 4.99.2. The advisory does not provide separate technical details for CVE-2026-40686 by itself, so the most reliable defensive takeaway is to patch the bundled Exim package through the supported cPanel release channels.

Vendor
cPanel
Product
cPanel/WHM
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-05
Original CVE updated
2026-05-11
Advisory published
2026-05-05
Advisory updated
2026-05-11

Who should care

Administrators of cPanel/WHM servers, especially internet-facing mail hosts and managed hosting environments running Exim through cPanel packages.

Technical summary

According to cPanel’s official advisory, several Exim vulnerabilities affect versions prior to 4.99.2, including CVE-2026-40686. cPanel states that a fixed cpanel-exim package has been released and is included in cPanel/WHM versions 136.0.7, 134.0.23, 118.0.64, and 110.0.112. The advisory links the remediation to CPANEL-53011 and explicitly says the update fixes CVE-2026-40684, CVE-2026-40685, CVE-2026-40686, and CVE-2026-40687. No additional per-CVE impact details are provided in the supplied source.

Defensive priority

High for any cPanel/WHM deployment that uses Exim and has not yet been updated to a patched build.

Recommended defensive actions

  • Upgrade cPanel/WHM to one of the vendor-patched builds: 136.0.7, 134.0.23, 118.0.64, or 110.0.112.
  • Verify that the installed cpanel-exim package is at version 4.99.2 or the vendor-fixed equivalent.
  • Prioritize patching on servers that handle external mail traffic or are exposed to the internet.
  • Check vendor change logs for CPANEL-53011 to confirm the fix is present in your release stream.
  • If you cannot patch immediately, increase monitoring of mail service logs and administrative access until the update is applied.

Evidence notes

Primary evidence comes from cPanel’s official support article published 2026-05-05 and updated 2026-05-11. The article states that Exim versions prior to 4.99.2 are impacted and that the fix is included in cPanel/WHM versions 136.0.7, 134.0.23, 118.0.64, and 110.0.112. No CVSS score, exploit details, or standalone technical description for CVE-2026-40686 were provided in the supplied corpus.

Official resources

cPanel published the advisory for CVE-2026-40686 on 2026-05-05T15:45:46Z and updated it on 2026-05-11T20:04:50Z. The supplied source does not indicate a separate issue date beyond that vendor publication timeline.