Reference page — cumulative record through Wednesday, October 7, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2025-42599
Qualitia Active! Mail
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U H H H 9.8 .0330 88.1 YES
AFFECTED
Product Versions Fixed
Active! mail 6 BuildInfo: 6.60.05008561 and earlier – —
TIMELINE
Apr 16 Reserved by jpcert
Apr 18 Published (CNA: jpcert)
Apr 28 Added to CISA KEV, remediation due 2025-05-19
Description
Active! mail 6 BuildInfo: 6.60.05008561 and earlier contains a stack-based buffer overflow vulnerability. Receiving a specially crafted request created and sent by a remote unauthenticated attacker may lead to arbitrary code execution and/or a denial-of-service (DoS) condition.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| April 16, 2025 | Reserved | Reserved by jpcert |
| April 18, 2025 | Published | Published (CNA: jpcert) |
| April 28, 2025 | KEV ADDED | Added to CISA KEV, remediation due 2025-05-19 |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| QUALITIA CO., LTD. | Active! mail 6 | — | BuildInfo: 6.60.05008561 and earlier | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2025-42599 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, October 7, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.