Libraesva ESG issues emergency fix for bug exploited by state hackers

Libraesva ESG issues emergency fix for bug exploited by state hackers

Libraesva has issued an emergency security update to address a command injection vulnerability (CVE-2025-59689) in its Email Security Gateway that was exploited by state-sponsored threat actors. The flaw allows malicious emails with crafted attachments to execute arbitrary shell commands, impacting thousands of users worldwide. #Libraesva #CVE-2025-59689

Keypoints

  • The vulnerability in Libraesva ESG affects all versions from 4.5 onwards until the latest patches.
  • The security flaw is triggered by maliciously crafted compressed email attachments that run arbitrary commands.
  • Libraesva responded with an emergency patch deployed automatically within 17 hours of discovery.
  • The fix includes sanitization improvements, breach indicators scanning, and a self-assessment tool.
  • There has been confirmed use of this vulnerability in targeted attacks by a suspected foreign state actor.

Read More: https://www.bleepingcomputer.com/news/security/libraesva-esg-issues-emergency-fix-for-bug-exploited-by-state-hackers/