Patch/Configuration Management, Vulnerability Management, Email security

CISA adds critical RoundCube Webmail vulnerabilities to KEV catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities affecting the RoundCube Webmail platform to its Known Exploited Vulnerabilities (KEV) catalog. The flaws are tracked as CVE-2025-49113 and CVE-2025-68461, Security Affairs reports.

The most critical vulnerability, CVE-2025-49113, is a deserialization of untrusted data flaw with a CVSS score of 9.9. This vulnerability, which reportedly went unnoticed for over a decade, allows authenticated users to achieve remote code execution by exploiting improper validation in the upload.php script. The second flaw, CVE-2025-68461, is a cross-site scripting (XSS) vulnerability with a CVSS score of 7.2, stemming from improper handling of SVG documents. Both vulnerabilities have been addressed by RoundCube in versions 1.5.10 and 1.6.11, respectively. The platform is widely used, with an estimated 53 million hosts potentially impacted, and has been a target for advanced persistent threat groups like APT28 and Winter Vivern.

Federal agencies are mandated to remediate these flaws by March 10, 2026, aligning with Binding Operational Directive 22-01. Private sector organizations are also strongly urged to consult the KEV catalog and prioritize patching these vulnerabilities to mitigate the risk of compromise, credential theft, and espionage.

Source: Security Affairs

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds