HomeSecurityVulnerability in Active! Mail used for attacks in Japan

Vulnerability in Active! Mail used for attacks in Japan

A previously unknown zero-day vulnerability in Active! Mail allows malicious users to remotely execute code and is currently being actively used in attacks against large organizations in Japan.

Vulnerability in Active! Mail used for attacks in Japan

Active! Mail is a web-based email client, originally developed by TransWARE and later acquired by Qualitia (Japanese companies). Although it does not have the international appeal of services such as Gmail or Outlook, it is widely used in Japan as part of corporate solutions, particularly by large enterprises, universities, government agencies and banks.

Qualitia reports that the software is installed in over 2,250 organizations, serving over 11 million users, making it an important tool for the Japanese electronic communication.

See also: SQL Injection vulnerabilities affect popular TP-Link routers

At the end of last week, the company released a security advisory for a critical stack-based buffer overflow issue (CVE-2025-42599, CVSS score: 9.8), which affects all versions of Active! Mail up to 'BuildInfo: 6.60.05008561' (on all supported platforms).

The advisory warns that if a specially crafted request is sent by a remote attacker, it may lead to arbitrary code execution or even a denial of service (DoS).

While Qualitia is still investigating whether the issue has already been exploited, Japan's CERT has confirmed that the vulnerability is being actively exploited, urging users to immediately upgrade to version 6.60.06008562.

Kagoya Japan, a hosting and IT services provider, reported multiple attacks over the weekend, leading it to temporarily suspend some services. In a statement, the provider said: “We believe the issue is related to the vulnerability recently disclosed by Qualitia.”

A similar service outage due to potential exploitation attempts was also reported by web hosting and IT service provider, WADAX.

See also: North Korean hackers Kimsuky exploit RDP vulnerability

Active! Mail vulnerability

"At this time, we cannot ensure the safe use of the service for our customers," WADAX announced. "For this reason, placing the security of our customers as a priority, we have temporarily suspended the Active! email service as a precautionary measure."

Japanese internet service provider IIJ also announced that it was affected by attacks exploiting CVE-2025-42599, putting customer information at risk . The attacks were first detected on April 15, indicating the exploit as a zero-day.

Macnica security researcher Yutaka Sejiyamatold BleepingComputer that at least 227 Active! servers are exposed online and may be targets of these attacks, with 63 of them being used at universities.

Japan CERT has suggested specific measures to address the problem for those who cannot apply the update immediately: e.g. configuring the Web Application Firewall (WAF) to enable HTTP request body inspection and block multipart/form-data headers if their size exceeds a certain limit.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: New Windows NTLM vulnerability used in attacks

It is also recommended that Active! Mail usage be reduced. If the application is not absolutely necessary, organizations can switch to more secure or widely supported email tools (at least until the issue is addressed). If Active! Mail must remain active, its use should be limited to isolated environments and on devices that do not contain sensitive data.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS