Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilitygovernment-vulnerability-catalograpid-weaponizationinternet-facing-service-vulnerability

CISA Adds Actively Exploited Roundcube Webmail Vulnerabilities to KEV Catalog

Updated 3mo agoFirst seen Feb 21, 202610 sources

CISA added two Roundcube Webmail vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation: CVE-2025-49113 (CVSS 9.9), a deserialization issue enabling authenticated remote code execution due to improper validation of the _from URL parameter in program/actions/settings/upload.php, and CVE-2025-68461 (CVSS 7.2), an XSS flaw involving the animate tag in an SVG document. CISA directed U.S. Federal Civilian Executive Branch (FCEB) agencies to remediate by 2026-03-13, and advised applying vendor mitigations per guidance (or discontinuing use if mitigations are unavailable).

The KEV repository updates for 2026-02-20 reflect both Roundcube entries, including mappings to CWE-502 (deserialization) and CWE-79 (XSS) and links to Roundcube advisories/releases. Reporting also noted that researchers observed rapid attacker uptake of CVE-2025-49113 after disclosure, including claims that attackers quickly “diffed and weaponized” the bug and that exploit access was offered for sale shortly after. Separate reporting about BeyondTrust Remote Support/Privileged Remote Access (CVE-2026-1731) describes a different KEV addition and is not part of the Roundcube event.

Share:
CISA Adds Actively Exploited Roundcube Webmail Vulnerabilities to KEV Catalog
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Feb 23, 20264mo ago

Nuclei template released for detecting CVE-2025-68461 exposure

A ProjectDiscovery pull request added a Nuclei template to identify Roundcube instances vulnerable to CVE-2025-68461 by checking the exposed rcversion value. The template targeted versions earlier than 1.5.12 and 1.6.12.

Feb 20, 20264mo ago

CISA KEV update expands with additional exploited products

On the same February 20, 2026 KEV update cycle, CISA's catalog also included exploited vulnerabilities affecting GitLab, Dell RecoverPoint for Virtual Machines, and Synacor Zimbra Collaboration Suite. The catalog version increased from 2026.02.19 to 2026.02.20 and the total count rose from 1524 to 1526.

CISA adds two Roundcube flaws to the KEV catalog

CISA updated its Known Exploited Vulnerabilities catalog to add Roundcube Webmail flaws CVE-2025-49113 and CVE-2025-68461 based on evidence of active exploitation. The update was published on February 20, 2026, and set a federal remediation deadline in mid-March 2026.

Dec 1, 20257mo ago

Roundcube patches CVE-2025-68461 XSS flaw

Roundcube fixed CVE-2025-68461, an SVG animate tag cross-site scripting vulnerability, in versions 1.6.12 and 1.5.12. Reporting indicates the patch was released in December 2025.

Jun 4, 20251y ago

Attackers weaponize CVE-2025-49113 after disclosure

Researchers at FearsOff said attackers weaponized the Roundcube CVE-2025-49113 flaw within 48 hours of its public disclosure. This showed the vulnerability quickly moved from disclosure to active offensive use.

Exploit for CVE-2025-49113 offered for sale

An exploit targeting Roundcube CVE-2025-49113 was reportedly offered for sale shortly after disclosure. One report places this sale on June 4, 2025, indicating rapid weaponization interest.

Jun 1, 20251y ago

Roundcube patches CVE-2025-49113 remote code execution flaw

Roundcube released fixes for CVE-2025-49113, a deserialization vulnerability that can lead to authenticated remote code execution, in versions 1.6.11 and 1.5.10 LTS. Multiple reports state the flaw was patched on June 1, 2025.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

25 LINKEDOpen in app
Threat actors
2 linked
Affected products
3 linked
Roundcube WebmailGitlabZimbra Collaboration Suite
Organizations
14 linked
GitLabRoundcubeShadowServer FoundationCpanelFearsOffPositive TechnologiesIspconfigDell TechnologiesZimbraShodanPleskTinesDirectadminSecurity Affairs
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.