Loading
Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a fix has been released in 5.0.31. For ESG 5.1 a fix has been released in 5.1.20. For ESG 5.2 a fix has been released in 5.2.31. For ESG 5.4 a fix has been released in 5.4.8. For ESG 5.5. a fix has been released in 5.5.7.
Use CWE-77, Libraesva vendor hub and Email Security Gateway product page to widen CVE-2025-59689 into its surrounding weakness, vendor, and product context.
Additional editorial context is available in Cybersecurity Weekly Roundup: April 22, 2026 — Critical Zero-Days and Framework Failures.