# Active! mail flaw exploited in wild

Published: 2025-04-17 · Severity: critical · Sectors: technology
Canonical: https://vorant.io/reports/3fc34de5-4a54-5ddd-91e3-dfb87a7b588a/active-mail-flaw-exploited-in-wild

> A critical stack-based buffer overflow in Qualitia's Active! mail webmail system is being actively exploited to achieve remote code execution or DoS.

IPA and JVN disclosed CVE-2025-42599, a stack-based buffer overflow vulnerability in Qualitia's Active! mail webmail product affecting version 6 BuildInfo 6.60.05008561 and earlier. The flaw carries a CVSS v3 score of 9.8 (critical) and allows a remote attacker to send a specially crafted request to execute arbitrary code or cause a denial-of-service condition on the affected system.

The advisory explicitly states that exploitation of this vulnerability has already been observed in the wild, making immediate patching a priority. Qualitia has released a fixed version, Active! mail 6 BuildInfo 6.60.06008562, and IPA urges affected organizations to update as soon as possible based on vendor-provided guidance.

## Mentioned in this report

- Vulnerabilities: CVE-2025-42599 (KEV)

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/20250418-jvn.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/3fc34de5-4a54-5ddd-91e3-dfb87a7b588a/active-mail-flaw-exploited-in-wild.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
