In late September 2025, CISA issued a public warning about the active exploitation of a critical command injection vulnerability, tracked as CVE-2025-59689 , in Libraesva ESG (Email Security Gateway) devices .
See also: CISA added Sudo vulnerability to KEV List

This vulnerability has quickly emerged as a favorite target for malicious actors due to its ease of exploitation and the widespread use of Libraesva ESG as a first line of defense in corporate and government email infrastructure.
The vulnerability allows unauthenticated attackers to execute arbitrary system commands on affected devices, leading to a significant risk of email compromise, data exfiltration, and lateral movement within networks.
The initial discovery of this security vulnerability came after multiple security firms observed anomalous traffic directed to publicly accessible Libraesva ESG devices in Europe and North America. Attackers quickly deployed PoCs, exploiting the vulnerability’s simple payload delivery – typically via a specially crafted HTTP POST request to an exposed management interface.
See also: CISA: Requires Cisco to patch zero-day vulnerabilities

Organizations relying on Libraesva ESG appliances for spam and phishing defense are at immediate risk, with exploitation often leading to complete device takeover.
CISA analysts noted that attackers exploiting CVE-2025-59689 did so with great speed and stealth, leaving minimal traces in security logs. Their research revealed that successful exploitation allowed payloads that enabled remote shell access, installation of additional malware packages, and use of the ESG device as a pivot point for internal reconnaissance.
CISA documented several incidents where attackers deployed reverse shells to establish permanent access after the breach.
The infection mechanism at the heart of CVE-2025-59689 is a classic OS command injection. An attacker submits a specially crafted request to the web management API with embedded command payloads in user-supplied parameters. This command demonstrates how the vulnerability allows an external actor to create a remote shell directly on the attacker's system, bypassing authentication checks.
See also: CISA: Chrome zero-day vulnerability in KEV Catalog

CISA researchers found that many incidents occurred due to ESG devices not having recent security updates, highlighting the necessity for timely remediation.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
