State-Sponsored Hackers Exploiting Libraesva Email Security Gateway Vulnerability
To fix a flaw in its Email Security Gateway (ESG) product that it claims has been used by state-sponsored threat actors, Libraesva has issued a security update.
The vulnerability, identified as CVE-2025-59689, has a medium severity CVSS score of 6.1.
A malicious email with a specially constructed compressed attachment might cause a command injection weakness in Libraesva ESG, which could let arbitrary commands to be executed as a non-privileged user, the company noted in an alert.
This happens as a result of files in certain compressed archive formats being improperly sanitized when active code is removed.
In the event of a hypothetical attack, a threat actor may use the application's flawed sanitization logic to eventually run arbitrary shell commands by sending an email read...

