<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>cybercrime.club</title><link>https://cybercrime.club/tags/smtp/</link><description>Infrastructure security news for people who build infrastructure.</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Sun, 03 May 2026 11:09:09 -0400</lastBuildDate><atom:link href="https://cybercrime.club/tags/smtp/" rel="self" type="application/rss+xml"/><item><title>Exim 4.99.2 Patches Four Mail Server Flaws: Heap Corruption via JSON Headers, DNS Poisoning, and SPA Auth Bugs</title><link>https://cybercrime.club/posts/exim-4-99-2-cve-2026-40684-40687-mail-server-heap-corruption/</link><pubDate>Sun, 03 May 2026 11:09:09 -0400</pubDate><guid>https://cybercrime.club/posts/exim-4-99-2-cve-2026-40684-40687-mail-server-heap-corruption/</guid><description>Exim 4.99.2 fixes four memory-safety bugs (CVE-2026-40684 through 40687) in the world's most-deployed MTA, including a JSON heap-write reachable from untrusted headers.</description><category>vulnerabilities</category></item></channel></rss>