LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-59689: Libraesva Email Security Gateway Command Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Sep 29, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Oct 20, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-59689 to its Known Exploited Vulnerabilities catalog on Sep 29, 2025, with a federal patch deadline of Oct 20, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Libraesva Email Security Gateway (ESG) contains a command injection vulnerability which allows command injection via a compressed e-mail attachment.

CVE-2025-59689 is a command injection vulnerability in Libraesva Email Security Gateway (ESG). It allows an attacker to inject commands through a compressed email attachment. Because ESG sits in the email path and processes attachments for many organizations, successful abuse can give an attacker a foothold on a security appliance that handles sensitive mail flow. Confirm all product-specific details against the vendor advisory.

CISA lists the issue under CWE-77 and notes that the required action is to apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use if mitigations are unavailable. Known ransomware use is not documented.

How it works

CWE-77 covers improper neutralization of special elements used in a command. In this class of flaw, data that should be treated only as content is instead interpreted by a shell or command interpreter. For Libraesva ESG the CISA summary states that command injection is possible via a compressed email attachment. An attacker who can deliver a specially crafted compressed attachment therefore has a path to cause the gateway to execute unintended commands in the context of the process that handles the attachment.

Exact payload construction, required attachment formats, and privilege level of the resulting process are not provided in the public summary; treat those as details that must be confirmed against the vendor advisory. The practical risk is that a device intended to protect email becomes a vector for remote command execution, potentially allowing further lateral movement or data access from the mail security tier.

Am I affected? How to find it in your systems

Libraesva Email Security Gateway is typically deployed as an on-premises appliance, virtual appliance, or cloud-managed email security service that sits in the inbound/outbound mail path. Inventory every instance that processes or scans email attachments for your organization.

Absence of obvious log anomalies does not prove safety; prioritize inventory and version confirmation.

How to remediate

Patch first. Apply the vendor-supplied update or mitigation instructions referenced in the official advisory for Libraesva Email Security Gateway. CISA’s required action is explicit: apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls that limit both delivery of the malicious attachment and the impact of any successful injection.

These steps buy time; they do not replace the vendor fix.

If your data may have been exposed

Actively exploited command-injection flaws on email security gateways can lead to unauthorized access to mail content, credentials, or the broader network. Known ransomware use of this specific CVE is not documented, but any successful compromise should be treated as a potential breach. Review mail-gateway and authentication logs for indicators of compromise, rotate credentials that may have traversed the appliance, and follow your incident-response plan. You can also run a free exposure scan of your email addresses against known breach data sets to determine whether related accounts already appear in public breach corpora.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedLibraesva · Email Security Gateway
WeaknessCWE-77
Added to CISA KEVSep 29, 2025
Federal patch deadlineOct 20, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities