Skip to content
COOEY

EXPOSURES › CVE-2025-42599

CVE-2025-42599

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-04-28 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-42599 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

Qualitia Active! Mail has a remotely exploitable buffer overflow vulnerability currently under active exploitation in the wild.

A stack-based buffer overflow in Qualitia Active! Mail allows unauthenticated attackers to execute arbitrary code or cause a denial-of-service, and is currently being exploited. DIB organizations using this product face immediate risk of compromise and potential CMMC compliance failures. Immediately assess usage and apply available mitigations.

Shame score — The vulnerability's remote, unauthenticated exploitation and active exploitation demonstrate a significant failure in secure coding practices and timely patching.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Qualitia Active! Mail contains a stack-based buffer overflow vulnerability that allows a remote, unauthenticated attacker to execute arbitrary or trigger a denial-of-service via a specially crafted request.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.