CVE-2025-59710: Kovai BIZTALK360

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

An issue was discovered in Biztalk360 before 11.5. Because of incorrect access control, any user is able to request the loading a DLL file. During the loading, a method is called. An attacker can craft a malicious DLL, upload it to the server, and use it to achieve remote code execution on the server.

Affected products

  • Kovai BIZTALK360: before 11.6.3963.2611 (fixed in 11.6.3963.2611)

Published 2026-04-03. Last modified 2026-07-24.