LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-42599: Qualitia Active! Mail Stack-Based Buffer Overflow Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 28, 2025
CVSS 9.8 · Critical⚠ Actively exploited (CISA KEV)
9.8
CVSS score
Critical
Severity
Active
CISA KEV
No
Ransomware use
May 19, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-42599 to its Known Exploited Vulnerabilities catalog on Apr 28, 2025, with a federal patch deadline of May 19, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Active! mail 6 BuildInfo: 6.60.05008561 and earlier contains a stack-based buffer overflow vulnerability. Receiving a specially crafted request created and sent by a remote unauthenticated attacker may lead to arbitrary code execution and/or a denial-of-service (DoS) condition.

CVE-2025-42599 is a stack-based buffer overflow in Qualitia Active! Mail. A remote, unauthenticated attacker can send a specially crafted request that either executes arbitrary code on the host or crashes the service into a denial-of-service condition. Because the flaw requires no credentials and can lead to full system compromise, any internet-facing or poorly segmented instance of this mail product is a high-priority risk for IT and security teams.

Public detail on exact build numbers and exploit mechanics is limited; always confirm the precise scope and fixed releases against the vendor advisory before acting.

How it works

The vulnerability is classified as CWE-121 (stack-based buffer overflow). In this class of flaw, the application copies attacker-controlled data into a fixed-size buffer allocated on the stack without adequate length checking. When the data exceeds the buffer, it overwrites adjacent stack memory—return addresses, frame pointers, or other control data.

An unauthenticated remote attacker abuses the condition by submitting a specially crafted request to the Active! Mail service. Successful overflow can redirect execution flow to attacker-supplied code (arbitrary code execution) or simply corrupt critical structures enough to crash the process (denial of service). No authentication or prior access is required; the attack surface is whatever network interface the mail service listens on.

Am I affected? How to find it in your systems

Qualitia Active! Mail is typically deployed as an on-premises or private-cloud mail server handling SMTP, POP, IMAP or web-mail traffic. It may appear on dedicated mail hosts, virtual appliances, or as a component inside larger collaboration stacks.

How to remediate

Apply the vendor-supplied update or patch that addresses CVE-2025-42599 as soon as it is available and tested in your environment. Follow the exact installation and verification steps given in the Qualitia advisory.

After patching, harden the remaining attack surface:

If mitigations cannot be applied, CISA advises discontinuing use of the product until a fix is available.

If you can't patch immediately

Implement compensating controls to reduce exposure while a permanent fix is prepared:

These measures lower but do not eliminate risk; schedule the official patch as the primary remediation.

If your data may have been exposed

Actively exploited remote-code-execution vulnerabilities frequently precede data breaches. If you discover evidence of successful exploitation—unexpected processes, outbound connections, or missing logs—treat the host as compromised, isolate it, and begin incident-response procedures. While ransomware use of this specific CVE is not documented, any code-execution foothold can be leveraged for further attacks. As a quick check for previously leaked credentials, you can run a free exposure scan of your email addresses against known breach data sets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedQualitia · Active! Mail
WeaknessCWE-121
CVSS base score9.8 (Critical)
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
PublishedApr 18, 2025
Added to CISA KEVApr 28, 2025
Federal patch deadlineMay 19, 2025
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities