CISA Lists Two Actively Exploited Roundcube Vulnerabilities in KEV Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced on Friday that it has included two vulnerabilities affecting the Roundcube webmail platform in its Known Exploited Vulnerabilities (KEV) catalog, citing indications that the flaws are being abused in the wild.
The two issues added are detailed below:
CVE-2025-49113 (CVSS 9.9) – A deserialization of untrusted data weakness that permits remote code execution by users with valid credentials. The problem stems from the _from parameter in a URL not being validated in program/actions/settings/upload.php. A patch for this issue was made available in June 2025.
CVE-2025-68461 (CVSS 7.2) – A cross-site scripting (XSS) flaw that can be triggered through the animate tag inside an SVG file. This vulnerability was addressed with a fix in December 2025.
Dubai-based security firm FearsOff, whose founder and CEO Kirill Firsov is credited with reporting CVE-2025-49113, warned that attackers quickly analyzed and turned the bug into a working exploit within 48 hours of its public disclosure. According to FearsOff, a weaponized exploit for the vulnerability was later put up for sale on June 4, 2025.
Firsov also said the defect can be reliably exploited on default Roundcube installations and that the vulnerable code had been present in the project for more than a decade before discovery.
At this time CISA has not attributed the recent exploitation to any specific group. However, past Roundcube flaws have been adopted by state-aligned threat actors, including known campaigns linked to APT28 and the cluster referred to as Winter Vivern.
Federal Civilian Executive Branch (FCEB) agencies have been instructed to remediate the listed vulnerabilities by March 13, 2026, as part of efforts to protect government networks from the ongoing threat.
For more information on the KEV catalog, consult CISA’s resource page: https://www.cisa.gov/known-exploited-vulnerabilities-catalog