Libraesva issued an emergency update for its Email Security Gateway (ESG) after discovering active exploitation of a command injection vulnerability, CVE-2025-59689, by suspected state-sponsored actors. The flaw allows arbitrary command execution via malicious email attachments and affects all ESG versions from 4.5 onward. The patch, released within 17 hours of detection, includes a sanitization fix, automated compromise scanning, and a self-assessment module.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On September 23-24, 2025, Libraesva and multiple security outlets disclosed that CVE-2025-59689 was being exploited in the wild and published technical details describing improper sanitization of files inside certain archive formats as the root cause. Customers were urged to deploy patches quickly because exploitation can be delivered through email-borne attachments.
After detecting the abuse, Libraesva issued security updates for supported 5.x branches within 17 hours to fix the command injection flaw affecting ESG versions 4.5 through 5.5.x before 5.5.7. The unsupported 4.x branch remained end-of-life and did not receive a fix.
Libraesva confirmed at least one real-world exploitation incident involving CVE-2025-59689, where a malicious email with a specially crafted compressed attachment triggered command execution on one Email Security Gateway appliance. The company assessed the operation as a precise attack by a foreign hostile state entity.
7 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcescworld.com
Open sourcehelpnetsecurity.com
Open sourcesecurityaffairs.com
Open sourcesecurityonline.info
Open sourcebleepingcomputer.com
Open sourcesecurityonline.info
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.