logo

Libraesva ESG issues emergency fix for bug exploited by state hackers

ID: 9706aa48-3839-5bdf-ada3-62649cd04d7b

STIX ID: report--9706aa48-3839-5bdf-ada3-62649cd04d7b

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2025-09-23

Date Updated: 2026-07-19

Author: Bill Toulas

...
...

Libraesva released an emergency update for its Email Security Gateway to fix CVE-2025-59689, a command-injection flaw exploitable via specially crafted compressed email attachments that can execute arbitrary shell commands as a non-privileged user; the vendor reports at least one confirmed exploitation by an actor believed to be a foreign hostile state and has deployed patches and automated IOCs and self-assessment checks for supported versions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.