Exim runs as the MTA on essentially every cPanel and DirectAdmin server, listens on the internet, and runs partly as root. When it has a security problem, every shared hosting provider has the same problem on the same day. 2026 has brought two significant rounds of fixes, and both panels have moved to Exim 4.100. This guide covers what was fixed, which panel builds contain the fixes, what changed in the 4.100 series that can affect a customised configuration, and how to check a server.
Table of Contents
Short answer: CVE-2026-40684 to 40687 were fixed in Exim 4.99.2 and the August .forward privilege escalation in the 4 August panel releases (cPanel 136.0.32, 134.0.48 and 110.0.137; DirectAdmin via CustomBuild), and both panels now ship Exim 4.100. Confirm with exim -bV plus the panel build number, rebuild exim_conf on DirectAdmin, and check that custom routers still parse, because 4.100 rejects removed options and weak TLS cipher lists.
The 2026 fixes
The first round, CVE-2026-40684 through CVE-2026-40687, was addressed in Exim 4.99.2. cPanel shipped it in builds 136.0.7 and 134.0.23, with the corresponding 132 and 110 builds following. DirectAdmin picked it up through CustomBuild within days. The flaws were in message and protocol handling reachable from the network; treat them as remotely exploitable and assume any server still on an earlier 4.99 build is exposed.
The second round, in August, was a local privilege escalation through .forward file processing. Exim evaluates a user’s .forward filter with elevated privileges in some code paths, and a crafted filter could escape them. cPanel bundled the fix into the 4 August security release alongside CVE-2026-58048 and CVE-2026-58047, in builds 136.0.32, 134.0.48 and 110.0.137. On a shared server this one matters more than it sounds: every hosting customer can write a .forward file, so it turns any web shell into root.
Since then cPanel has moved to Exim 4.100.1 in version 138, and DirectAdmin’s CustomBuild tracks 4.100 as its current version. The full cPanel build list for the year is in our CVE and build number guide.
Which version you are running
On either panel:
exim -bV | head -3
The first line prints the version and build date. On cPanel, cross-check the panel version, since the fix is tied to the build rather than to the upstream Exim number:
whmapi1 version
rpm -q exim
On DirectAdmin:
da build versions | grep -i exim
rpm -q exim || dpkg -l exim
If CustomBuild reports a newer version available, update it:
da build update
da build exim
da build exim_conf
exim_conf regenerates /etc/exim.conf from the current template, which is where the .pre.conf and .post.conf includes are wired in.
What changed in 4.100 for administrators
The 4.100 series is an evolution of 4.99 rather than a rewrite, but a few changes matter to anyone with a customised configuration.
Expansion of some legacy options now logs deprecation warnings, and options removed after their deprecation period cause a configuration error at startup. Run exim -bV after every update; it exits non-zero and names the line if something no longer parses. This is the single most important habit, because a failed Exim start on a shared server stops all mail.
TLS defaults are stricter. The minimum protocol version and cipher list have tightened, and tls_require_ciphers values copied from old guides that name RC4 or 3DES ciphers will either be ignored or rejected. Delete such lines and let the defaults apply. Servers that relay to a smarthost with hosts_require_tls are unaffected as long as the smarthost supports TLS 1.2 or newer, which every serious relay does.
DKIM handling gained clearer verification results in $dkim_verify_status and related variables, and signing with the dkim_timestamps option is available for expiring signatures. Existing signing configurations continue to work.
The $h_ header expansion and ACL condition behaviour around malformed headers was tightened as part of the security work, so a custom ACL that relied on lenient parsing of broken From: lines may now reject mail it previously accepted. Check exim_rejectlog for an increase in header-related rejections after the update.
DirectAdmin 1.704 unified the SpamAssassin and Rspamd header names it adds, which coincides with the Exim change for many servers; if your custom routers or transports match on X-Spam-Status, confirm the header name your build emits. Rspamd versus SpamAssassin differences are covered in our DirectAdmin filtering guide.
Custom configuration survival
cPanel regenerates /etc/exim.conf on every Exim update from the Advanced Editor’s stored snippets. Anything edited directly in the file is lost. DirectAdmin does the same from its template and the /etc/exim.*.conf includes. After the 4.100 update, check that your snippets still parse and still take effect:
exim -bV
exim -bP routers | grep -E '^[a-z_]+:'
exim -bP transports | grep -E '^[a-z_]+:'
The router and transport names you added should appear in the lists. A smarthost router that has silently vanished means the panel’s template moved the insertion point; on cPanel re-check the Advanced Editor, on DirectAdmin confirm the .pre.conf file names match what the new template includes with grep include_if_exists /etc/exim.conf.
Verify
Confirm the version is at or beyond the fixed build, restart Exim and send a test:
systemctl restart exim
systemctl is-active exim
echo test | mail -s "Exim update check" you@example.org
tail -5 /var/log/exim_mainlog
Then run the security audit script, which reports the Exim version alongside the panel build and flags a known-vulnerable combination. The common pitfall is trusting exim -bV alone on cPanel: cPanel backports fixes into its own package, so a version string of 4.99.2 on a build from before 4 August still lacks the .forward fix. Use the panel build number as the source of truth and keep automatic updates on; the 2026 pattern has been a root-level fix every two to three weeks.
Exim 4.100 security fixes at a glance

Official documentation: Exim documentation, DirectAdmin documentation, cPanel & WHM documentation.
Related guides: Choosing a VPS for a cPanel or DirectAdmin server in 2026 · Warm up a new mail server IP or sending domain without landing in spam · Find the source of outgoing spam on a cPanel server.
Frequently asked questions
Does the Exim .forward privilege escalation affect servers where users have no shell access?
Yes. A .forward file can be written through FTP, the file manager or a web shell in a compromised site, so every shared server is exposed regardless of shell access until the August build is applied.
How long does updating Exim to 4.100 take?
A few minutes on either panel: cPanel installs it during the normal upcp run, and on DirectAdmin da build exim followed by da build exim_conf compiles and reconfigures it with only a brief restart, so mail is queued rather than lost.
Can I undo this?
Not safely. Both panels regenerate the configuration for the version they ship and downgrading reopens the 2026 vulnerabilities; if a custom router breaks after the update, fix the snippet in the Advanced Editor or the .pre.conf include rather than rolling Exim back.