Libraesva has issued an urgent security update after discovering that state-sponsored threat actors have actively exploited a vulnerability in its Email Security Gateway (ESG) solution.
## The Vulnerability Details
The security flaw, designated CVE-2025-59689, has received a CVSS score of 6.1, placing it in the medium severity category. The vulnerability stems from a command injection weakness that allows attackers to execute unauthorized commands through malicious email attachments.
**How the Attack Works:**
– Cybercriminals send emails containing specially crafted compressed attachments
– The ESG system fails to properly sanitize these files during security scanning
– This improper handling allows attackers to execute arbitrary shell commands as a non-privileged user
## Affected Systems and Patches
The vulnerability impacts Libraesva ESG versions 4.5 through 5.5.x (before 5.5.7). The company has released security patches for the following versions:
– 5.0.31
– 5.1.20
– 5.2.31
– 5.3.16
– 5.4.8
– 5.5.7
**Important Note:** Systems running versions below 5.0 are no longer supported and require manual upgrades to receive security fixes.
## Active Exploitation Confirmed
Libraesva has confirmed at least one successful attack by what they describe as a “foreign hostile state entity.” The precision of the attack—targeting a single appliance—suggests sophisticated threat actors with specific objectives.
The company responded swiftly, deploying a fix within 17 hours of identifying the malicious activity. However, they have not disclosed additional details about the attack’s scope or the identity of the threat actors involved.
## Immediate Action Required
Given the active exploitation by state-sponsored hackers, organizations using Libraesva ESG must prioritize updating their systems immediately. The targeted nature of these attacks and the involvement of nation-state actors underscore the critical importance of rapid patch deployment.
System administrators should verify their current ESG version and apply the appropriate security update without delay to protect against potential compromise.
