• News/
  • https://www.bleepingcomputer.com/news/security/active-mail-rce-flaw-exploited-in-attacks-on-japanese-orgs/

Active! Mail RCE flaw exploited in attacks on Japanese orgs

BleepingComputer
·
Bill Toulas
·
Published Apr 22, 2025
·
Updated

An Active! Mail zero-day remote code execution vulnerability is actively exploited in attacks on large organizations in Japan. Active! mail is a web-based email client developed initially by TransWARE and later acquired by Qualitia, both Japanese companies. While it's not widely used worldwide like Gmail or Outlook, Active! is often used as a groupware component in Japanese-language environments of large corporations, universities, government agencies, and banks. According to the vendor, Active! is used in over 2,250 organizations, boasting over 11,000,000 accounts, making it a significant player in the country's business webmail market. Late last week, Qualitia released a security bulletin about a stack-based buffer overflow vulnerability tracked under CVE-2025-42599 (CVSS v3 score: 9.8, "critical") impacting all versions of Active! up to and including 'BuildInfo: 6.60.05008561' on all supported OS platforms. "If a maliciously crafted request is sent by a remote third party, there is a possibility of arbitrary code execution or a denial-of-service (DoS) condition being triggered," reads the bulletin. Although Qualitia mentions investigating whether the flaw has been exploited, Japan's CERT has confirmed its active exploitation status, urging all users to update to Active! Mail 6 BuildInfo: 6.60.06008562 as soon as possible. Japanese web hosting and IT services (SMB) provider Kagoya Japan reported several external attacks over the weekend, prompting it to temporarily suspend...

Read full article

Affected Software

2 affected components
Qualitia Active! Mail=6.60.05008561
Qualitia Active! Mail
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a zero-day remote code execution vulnerability in the Active! Mail software that is being actively exploited in cyber attacks targeting organizations in Japan.

2

What security implications are discussed?

The article details the risks associated with the exploitation of the Active! Mail vulnerability, which could allow attackers to execute remote code and potentially gain unauthorized access to sensitive information.

3

What products or software are affected?

The affected product is Qualitia Active! Mail, specifically version 6.60.05008561.

4

Who developed Active! Mail?

Active! Mail was initially developed by TransWARE and was later acquired by Qualitia.

5

How severe is the vulnerability reported in the article?

The vulnerability is classified as a zero-day exploit, indicating a high severity due to its active exploitation before a fix has been released.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203