PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-40686 cPanel CVE debrief

cPanel’s advisory groups CVE-2026-40686 with three related Exim issues and says the fix is already available in updated cPanel/WHM builds. The vendor notes that Exim versions prior to 4.99.2 are affected and that upgrading cPanel/WHM to a patched release updates cpanel-exim to 4.99.2. The advisory does not provide separate technical details for CVE-2026-40686 by itself, so the most reliable defensive takeaway is to patch the bundled Exim package through the supported cPanel release channels.

Vendor
cPanel
Product
cPanel/WHM
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-05
Original CVE updated
2026-05-11
Advisory published
2026-05-05
Advisory updated
2026-05-11

Who should care

Administrators of cPanel/WHM servers, especially internet-facing mail hosts and managed hosting environments running Exim through cPanel packages.

Technical summary

According to cPanel’s official advisory, several Exim vulnerabilities affect versions prior to 4.99.2, including CVE-2026-40686. cPanel states that a fixed cpanel-exim package has been released and is included in cPanel/WHM versions 136.0.7, 134.0.23, 118.0.64, and 110.0.112. The advisory links the remediation to CPANEL-53011 and explicitly says the update fixes CVE-2026-40684, CVE-2026-40685, CVE-2026-40686, and CVE-2026-40687. No additional per-CVE impact details are provided in the supplied source.

Defensive priority

High for any cPanel/WHM deployment that uses Exim and has not yet been updated to a patched build.

Recommended defensive actions

  • Upgrade cPanel/WHM to one of the vendor-patched builds: 136.0.7, 134.0.23, 118.0.64, or 110.0.112.
  • Verify that the installed cpanel-exim package is at version 4.99.2 or the vendor-fixed equivalent.
  • Prioritize patching on servers that handle external mail traffic or are exposed to the internet.
  • Check vendor change logs for CPANEL-53011 to confirm the fix is present in your release stream.
  • If you cannot patch immediately, increase monitoring of mail service logs and administrative access until the update is applied.

Evidence notes

Primary evidence comes from cPanel’s official support article published 2026-05-05 and updated 2026-05-11. The article states that Exim versions prior to 4.99.2 are impacted and that the fix is included in cPanel/WHM versions 136.0.7, 134.0.23, 118.0.64, and 110.0.112. No CVSS score, exploit details, or standalone technical description for CVE-2026-40686 were provided in the supplied corpus.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-40686 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-40686

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-40686 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-40686

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Vendor advisory source

    Unverified legacy reference

    URL: https://support.cpanel.net/hc/en-us/articles/40243823578903-Exim-CVE-2026-40684-CVE-2026-40685-CVE-2026-40686-and-CVE-2026-40687

    cpanel_changelog_rss

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.