logo

Active! Mail RCE flaw exploited in attacks on Japanese orgs

ID: a6695605-40bf-53ad-a15e-8ac12dd8efd2

STIX ID: report--a6695605-40bf-53ad-a15e-8ac12dd8efd2

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2025-04-22

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

An actively exploited zero-day (CVE-2025-42599, CVSS 9.8) affecting Active! Mail has been confirmed in attacks against large Japanese organizations, prompting vendor patches, hosting providers to suspend services, and at least one ISP (IIJ) to report customer data compromise; Japan CERT and vendors have issued update and WAF-based mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.