A vulnerability was found in Exim up to 4.99.1. It has been rated as critical. This affects an unknown part of the component SPA Authentication Driver. The manipulation leads to out-of-bounds write.
This vulnerability is referenced as CVE-2026-40687. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.