← Vulnerability feed

Vulnerability record · CVE-2025-59689 · published 19 September 2025

CVE-2025-59689: Libraesva ESG command injection via compressed email attachment

Libraesva · Email Security Gateway

Libraesva Email Security Gateway versions 4.5 through 5.5.x before 5.5.7 are vulnerable to command injection triggered by a compressed email attachment. Because the gateway processes inbound mail, a crafted attachment can execute commands on the appliance itself, which sits directly in the mail path. The vendor has released fixed builds for each affected branch.

6.1 CVSS 3.1 Medium CISA KEV since 29 Sep 2025 EPSS 1.9% · top 21.6% CWE-77 · Command injection
6.1CVSS 3.1 base score
1.9%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a fix has been released in 5.0.31. For ESG 5.1 a fix has been released in 5.1.20. For ESG 5.2 a fix has been released in 5.2.31. For ESG 5.4 a fix has been released in 5.4.8. For ESG 5.5. a fix has been released in 5.5.7.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe flaw is remotely reachable through email and listed in CISA KEV as exploited, though the CVSS score is only medium and user interaction is required.

What it is

Libraesva Email Security Gateway versions 4.5 through 5.5.x before 5.5.7 are vulnerable to command injection triggered by a compressed email attachment. Because the gateway processes inbound mail, a crafted attachment can execute commands on the appliance itself, which sits directly in the mail path. The vendor has released fixed builds for each affected branch.

Impact

An attacker who gets a crafted compressed attachment delivered can execute arbitrary commands on the ESG appliance, potentially compromising the mail gateway and any credentials or mail content it handles. The CVSS vector limits rated impact to low confidentiality and integrity with no availability loss, so the practical blast radius depends on the appliance's privileges and network position.

Attack surface

Reached remotely over the network through email delivery of a malicious compressed attachment; no authentication is required, but the CVSS vector requires user interaction, meaning a recipient or mail-processing action must trigger handling of the attachment.

Exploitation

CISA added this to the Known Exploited Vulnerabilities catalog on 2025-09-29 with a 2025-10-20 remediation due date, indicating known exploitation in the wild. EPSS is low at roughly 1.9 percent (78th percentile), and no ransomware campaign use is documented.

What to do

  • Upgrade to the fixed build for your branch: 5.0.31, 5.1.20, 5.2.31, 5.4.8, or 5.5.7, or later.
  • If patching cannot be completed by the CISA due date, apply the vendor's documented mitigations or discontinue use of the product per BOD 22-01 guidance.
  • Restrict management and outbound network access from the ESG appliance so injected commands have limited reach.
  • Block or quarantine compressed attachment types at the perimeter until all instances are confirmed patched.

Detection

  • Monitor ESG appliance logs and process telemetry for unexpected child processes spawned by mail-handling services.
  • Alert on outbound connections from the ESG appliance to unfamiliar hosts, which may indicate post-exploitation activity.
  • Search mail logs for compressed attachments that correlate in time with anomalous command execution or process creation on the gateway.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-59689 to the Known Exploited Vulnerabilities catalog on 29 September 2025 as "Libraesva Email Security Gateway Command Injection Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 20 October 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-59689 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-8037Progress LoadMaster API OS Command Injection RCEProgress LoadMaster (and related ADC products) contain an OS command injection flaw in multiple API command endpoints where unsanitized input is pass…KEVEPSS 77%analysed8.7CVE-2026-42271LiteLLM MCP test endpoints allow authenticated OS command injectionLiteLLM versions 1.74.2 through before 1.83.7 expose two MCP preview endpoints (POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list) th…KEVEPSS 13%analysed7.2CVE-2025-29635D-Link DIR-823X command injection in set_prohibiting handlerD-Link DIR-823X firmware (240126 and 240802) contains a command injection flaw in the /goform/set_prohibiting POST handler. An attacker who already h…KEVEPSS 88%analysed8.1CVE-2026-22719VMware Aria Operations command injection during support-assisted migrationVMware Aria Operations contains a command injection flaw (CWE-77) that an unauthenticated attacker can use to run arbitrary commands, potentially ach…KEVEPSS 18%analysed8.7CVE-2025-4008Meteobridge web interface command injection without authenticationThe Meteobridge web interface, built from CGI shell scripts and C, exposes an endpoint vulnerable to command injection. Because the endpoint also lac…KEVEPSS 94%analysed9.8CVE-2025-10035Fortra GoAnywhere MFT License Servlet deserialization to command injectionThe License Servlet in Fortra GoAnywhere MFT deserializes untrusted data, and an attacker who can present a validly forged license response signature…KEVEPSS 100%analysed8.8CVE-2020-25079D-Link DCS cameras authenticated command injection in ddns_enc.cgiD-Link DCS-2530L (before 1.06.01 Hotfix) and DCS-2670L (through 2.02) contain an authenticated command injection flaw in cgi-bin/ddns_enc.cgi. A user…KEVEPSS 54%analysed8.8CVE-2023-33538TP-Link router web interface command injection in WlanNetworkRpmTP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 contain a command injection flaw in the /userRpm/WlanNetworkRpm component of the route…KEVEPSS 42%analysed

Source: NIST National Vulnerability Database (record CVE-2025-59689), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.