← Vulnerability feed

Vulnerability record · CVE-2025-42599 · published 18 April 2025

CVE-2025-42599: Qualitia Active! mail stack buffer overflow allows remote code execution

Qualitia · Active\! Mail

Active! mail 6 (BuildInfo 6.60.05008561 and earlier) contains a stack-based buffer overflow (CWE-121). A remote unauthenticated attacker can trigger it with a specially crafted request, leading to arbitrary code execution or denial of service. It is a critical, network-reachable flaw in a mail product and is listed in CISA KEV.

9.8 CVSS 3.1 Critical CISA KEV since 28 Apr 2025 EPSS 3.3% · top 11.9% CWE-121 · Stack-based buffer overflow
9.8CVSS 3.1 base score
3.3%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
24 Sep 2026Last modified by NVD

Description

Active! mail 6 BuildInfo: 6.60.05008561 and earlier contains a stack-based buffer overflow vulnerability. Receiving a specially crafted request created and sent by a remote unauthenticated attacker may lead to arbitrary code execution and/or a denial-of-service (DoS) condition.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network, unauthenticated, no-interaction exploitation and confirmed inclusion in CISA KEV make this an urgent patch.

What it is

Active! mail 6 (BuildInfo 6.60.05008561 and earlier) contains a stack-based buffer overflow (CWE-121). A remote unauthenticated attacker can trigger it with a specially crafted request, leading to arbitrary code execution or denial of service. It is a critical, network-reachable flaw in a mail product and is listed in CISA KEV.

Impact

An attacker can execute arbitrary code on the mail server or crash it, gaining control of the host or disrupting mail service.

Attack surface

Reachable over the network via a crafted request to the Active! mail service; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are required.

Exploitation

CISA added it to KEV on 2025-04-28 with a 2025-05-19 remediation due, indicating known exploitation; EPSS 30-day probability is 0.03298 (87.9th percentile). No ransomware use is documented.

What to do

  • Apply the vendor fix from Qualitia for Active! mail 6; upgrade beyond BuildInfo 6.60.05008561 per the vendor advisory.
  • If no patch is available, follow CISA KEV required action: apply vendor mitigations or discontinue use of the product.
  • Restrict network access to the Active! mail service to trusted sources and place it behind filtering where feasible.
  • Monitor vendor and JVN advisories for updated fixed builds and interim mitigations.

Detection

  • Inspect Active! mail service logs for malformed or oversized requests and crashes/restarts around the same time.
  • Monitor for unexpected process crashes or abnormal child processes spawned by the mail service.
  • Alert on network traffic to the Active! mail service from untrusted or unexpected source addresses.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-42599 to the Known Exploited Vulnerabilities catalog on 28 April 2025 as "Qualitia Active! Mail Stack-Based Buffer Overflow Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 19 May 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-42599 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-7273Zyxel gs1900-8 firmware stack-based buffer overflow vulnerabilityA stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-base…KEVEPSS 2.5%8.1CVE-2021-27137DD-WRT UPnP M-SEARCH stack buffer overflowDD-WRT before 45724 contains an unsafe strcpy in the UPnP SSDP handling code (ssdp_msearch), reachable via an M-SEARCH request, that overflows a fixe…KEVEPSS 4.0%analysed9.3CVE-2025-53521F5 BIG-IP APM stack buffer overflow allows remote code executionA stack-based buffer overflow (CWE-121) exists in F5 BIG-IP Access Policy Manager when an APM access policy is configured on a virtual server. Specif…KEVEPSS 2.3%analysed8.8CVE-2008-0015Microsoft DirectShow Video ActiveX Control Stack Buffer OverflowA stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL) is reachable through the MPEG2TuneRequ…KEVEPSS 77%analysed7.7CVE-2025-20352Cisco IOS and IOS XE SNMP stack overflow allows DoS and root code executionA stack-based buffer overflow in the SNMP subsystem of Cisco IOS and IOS XE Software can be triggered by a crafted SNMP packet sent over IPv4 or IPv6…KEVEPSS 39%analysed9.8CVE-2025-32756Fortinet FortiMail, FortiNDR, FortiVoice, FortiRecorder, FortiCamera stack buffer overflowA stack-based buffer overflow (CWE-121/CWE-787) in multiple Fortinet products is reachable by sending HTTP requests with a specially crafted hash coo…KEVEPSS 30%analysed9.8CVE-2025-22457Ivanti Connect Secure, Policy Secure and ZTA Gateways stack buffer overflow RCEA stack-based buffer overflow (CWE-121/CWE-787) in Ivanti Connect Secure, Policy Secure and ZTA Gateways allows a remote, unauthenticated attacker to…KEVEPSS 100%analysed9.0CVE-2025-0282Ivanti Connect Secure stack buffer overflow enables unauthenticated RCEA stack-based buffer overflow (CWE-121/CWE-787) in Ivanti Connect Secure, Policy Secure and Neurons for ZTA gateways lets a remote, unauthenticated a…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2025-42599), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.