EXPOSURES › CVE-2025-42599
CVE-2025-42599
HIGH ⌖ ON CISA KEV · EXPLOITEDQualitia Active! Mail has a remotely exploitable buffer overflow vulnerability currently under active exploitation in the wild.
A stack-based buffer overflow in Qualitia Active! Mail allows unauthenticated attackers to execute arbitrary code or cause a denial-of-service, and is currently being exploited. DIB organizations using this product face immediate risk of compromise and potential CMMC compliance failures. Immediately assess usage and apply available mitigations.
Shame score — The vulnerability's remote, unauthenticated exploitation and active exploitation demonstrate a significant failure in secure coding practices and timely patching.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Qualitia Active! Mail contains a stack-based buffer overflow vulnerability that allows a remote, unauthenticated attacker to execute arbitrary or trigger a denial-of-service via a specially crafted request.