CVE-2025-49113Active Exploitation(debian / debian_linux)

CRITICALCVSS 8.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 11 mentions and remains active

Immediate actions

  • Patch debian debian_linux systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.

9.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-03-13. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-502

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • debian_linux
  • webmail

Threat summary

  • Active exploitation appears in 49 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 69 mentions across 30 observed days

What's happening

  • Active exploitation reported across 49 signals
  • Exploit tool or code specified in 11 signals
  • PoC mentioned or linked in 6 signals
  • Patch or workaround mentioned in 22 signals
  • Technical details provided in 31 signals
  • General: 8 classified signals
  • Disclosure: 7 classified signals
  • Peaked 21d ago at 11 mentions (2026-02-25); latest day: 1
  • 69 total mentions across 30 days

Affected systems

Products
debian_linuxwebmail

1 version affected across 2 products

Deep dive

Activity timeline69 mentions / 30d
036811Mentions · 2026-02-10: 1Mentions · 2026-02-18: 1Mentions · 2026-02-19: 1Mentions · 2026-02-20: 3Mentions · 2026-02-21: 1Mentions · 2026-02-22: 2Mentions · 2026-02-23: 9Mentions · 2026-02-24: 6Mentions · 2026-02-25: 11Mentions · 2026-02-26: 5Mentions · 2026-03-02: 1Mentions · 2026-03-04: 1Mentions · 2026-03-12: 1Mentions · 2026-05-07: 1Mentions · 2026-05-22: 1Mentions · 2026-05-25: 1Mentions · 2026-06-07: 1Mentions · 2026-06-14: 1Mentions · 2026-06-15: 1Mentions · 2026-07-07: 4Mentions · 2026-07-08: 2Mentions · 2026-07-09: 3Mentions · 2026-07-10: 3Mentions · 2026-08-11: 1Mentions · 2026-08-12: 2Mentions · 2026-08-13: 1Mentions · 2026-08-17: 1Mentions · 2026-08-23: 1Mentions · 2026-09-26: 1Mentions · 2026-09-30: 1PoC Mentioned / Linked · 2026-02-18: 1PoC Mentioned / Linked · 2026-06-15: 1PoC Mentioned / Linked · 2026-08-12: 1PoC Mentioned / Linked · 2026-08-17: 1PoC Mentioned / Linked · 2026-08-23: 1PoC Mentioned / Linked · 2026-09-26: 1Exploit Tool / Code · 2026-02-22: 1Exploit Tool / Code · 2026-02-23: 1Exploit Tool / Code · 2026-06-15: 1Exploit Tool / Code · 2026-07-07: 1Exploit Tool / Code · 2026-07-09: 1Exploit Tool / Code · 2026-07-10: 1Exploit Tool / Code · 2026-08-12: 2Exploit Tool / Code · 2026-08-13: 1Exploit Tool / Code · 2026-08-17: 1Exploit Tool / Code · 2026-08-23: 1Active Exploitation · 2026-02-20: 1Active Exploitation · 2026-02-21: 1Active Exploitation · 2026-02-22: 2Active Exploitation · 2026-02-23: 9Active Exploitation · 2026-02-24: 5Active Exploitation · 2026-02-25: 10Active Exploitation · 2026-02-26: 4Active Exploitation · 2026-03-02: 1Active Exploitation · 2026-07-07: 4Active Exploitation · 2026-07-08: 2Active Exploitation · 2026-07-09: 3Active Exploitation · 2026-07-10: 1Active Exploitation · 2026-08-11: 1Active Exploitation · 2026-08-12: 2Active Exploitation · 2026-08-13: 1Active Exploitation · 2026-08-17: 1Active Exploitation · 2026-09-26: 1Patch / Workaround · 2026-02-20: 1Patch / Workaround · 2026-02-23: 6Patch / Workaround · 2026-02-24: 4Patch / Workaround · 2026-02-25: 1Patch / Workaround · 2026-02-26: 2Patch / Workaround · 2026-07-07: 2Patch / Workaround · 2026-07-08: 2Patch / Workaround · 2026-08-12: 1Patch / Workaround · 2026-08-13: 1Patch / Workaround · 2026-08-17: 1Patch / Workaround · 2026-08-23: 1Technical Details · 2026-02-18: 1Technical Details · 2026-02-19: 1Technical Details · 2026-02-20: 1Technical Details · 2026-02-21: 1Technical Details · 2026-02-23: 7Technical Details · 2026-02-24: 4Technical Details · 2026-02-26: 1Technical Details · 2026-03-02: 1Technical Details · 2026-05-22: 1Technical Details · 2026-06-14: 1Technical Details · 2026-06-15: 1Technical Details · 2026-07-07: 1Technical Details · 2026-07-08: 2Technical Details · 2026-07-09: 1Technical Details · 2026-07-10: 1Technical Details · 2026-08-11: 1Technical Details · 2026-08-12: 2Technical Details · 2026-08-13: 1Technical Details · 2026-08-17: 1Technical Details · 2026-08-23: 102-1002-2002-2302-2603-1205-2506-1507-0908-1208-2309-30
Signal classification5 categories
Active Exploitation
4972.1%
General
811.8%
Disclosure
710.3%
PoC
22.9%
Exploit
22.9%
Referenced assets64 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-101
General1
2026-02-181
PoC1
2026-02-191
Disclosure1
2026-02-203
Active Exploitation1Disclosure2
2026-02-211
Active Exploitation1
2026-02-222
Active Exploitation2
2026-02-239
Active Exploitation9
2026-02-246
Active Exploitation5General1
2026-02-2511
Active Exploitation11
2026-02-265
Active Exploitation4Disclosure1
2026-03-021
Active Exploitation1
2026-03-041
General1
2026-03-121
General1
2026-05-071
General1
2026-05-221
Disclosure1
2026-05-251
General1
2026-06-071
General1
2026-06-141
Disclosure1
2026-06-151
PoC1
2026-07-074
Active Exploitation4
2026-07-082
Active Exploitation2
2026-07-093
Active Exploitation3
2026-07-103
Active Exploitation1Disclosure1General1
2026-08-111
Active Exploitation1
2026-08-122
Active Exploitation1Exploit1
2026-08-131
Active Exploitation1
2026-08-171
Active Exploitation1
2026-08-231
Exploit1
2026-09-261
Active Exploitation1
Full discourse20 posts
  • Check Point Research@_CPResearch_
    Active Exploitation

    0-Day Used by Lazarus in #DreamJob Campaign Against Defense Sector: 💥LPE vulnerability in Microsoft’s Afd.sys driver (CVE-2026-68820) 🧰New tools, including #Troy backdoor 🌍Compromised Roundcube servers (CVE-2025-49113) as infrastructure Read More : https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/ https://t.co/MIGKtH6FlM

    Post summary

    The Lazarus group reportedly exploited a zero‑day LPE in Microsoft’s Afd.sys (CVE‑2026‑68820) against defense targets, deploying new tools including the #Troy backdoor and leveraging compromised Roundcube servers.

    282431113936.3K
    25.5K followersView on X
  • Aircorridor@_aircorridor
    Disclosure

    Your email server might be vulnerable! CVE-2025-49113 allows attackers to compromise servers without authentication. https://hackers-arise.com/critical-remote-code-execution-rce-in-roundcube-cve-2025-49113-your-email-is-not-safe/ @three_cube @DI0256 @IamSmouk @co11ateral https://t.co/a9gyDen9o4

    Post summary

    The post announces the existence of CVE‑2025‑49113, a remote code execution flaw in Roundcube that permits unauthenticated exploitation, and directs readers to an external article for more information.

    345023714519.4K
    13.3K followersView on X
  • Densel@luckyhacker43
    Disclosure

    Critical RCE in Roundcube 🤯🔥 Your inbox could be the attack vector. CVE-2025-49113 allows Remote Code Execution on vulnerable Roundcube instances, putting countless email servers at risk. 🚨 👨‍💻 AirCorridor / Hackers-Arise 🔗 https://hackers-arise.com/critical-remote-code-execution-rce-in-roundcube-cve-2025-49113-your-email-is-not-safe/ #CyberSecurity #RCE https://t.co/pebfwoV57K

    Post summary

    The post announces the discovery of CVE‑2025‑49113, a critical RCE vulnerability in Roundcube that could expose countless email servers.

    53311437820.3K
    2.9K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    🚨 Suspected China-aligned UNK_MassTraction exploited now-patched Roundcube flaws against U.S. and Canadian university departments. IceCube stole credentials, 2FA data, and cookies, then used CVE-2025-49113 to drop VShell or a web shell. How the mail server compromise worked: https://thehackernews.com/2026/07/suspected-china-aligned-hackers-exploit.html

    Post summary

    Suspected China-aligned group exploited a recently patched Roundcube CVE, stealing credentials and dropping web shells, with a reference to a news article for more detail.

    1181681236.4K
    2.3M followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️ We added RoundCube Webmail vulnerabilities CVE-2025-49113 & CVE-2025-68461 to our Known Exploited Vulnerabilities Catalog. Visit https://go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/94NN54MXCA

    Post summary

    DHS lists two RoundCube Webmail CVEs as known exploited and advises applying mitigations, indicating confirmed real‑world use.

    41003343.6K
    291.5K followersView on X
  • blackorbird@blackorbird
    Active Exploitation

    Operation Dream Job #Lazarus exploited CVE-2026-68820, a zero-day vulnerability in the Microsoft AFD.sys driver, to deploy a new version of FudModule, Lazarus’ kernel-mode rootkit. https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/ Lazarus also used CVE-2025-49113 to exploit vulnerable Roundcube webmail servers. The compromised servers were infected with RelayShell, a PHP webshell that repurposes compromised web servers as relay nodes within the attacker’s command-and-control infrastructure.

    Post summary

    The post reports Lazarus actively exploiting CVE‑2026‑68820 and CVE‑2025‑49113 to deploy a kernel‑mode rootkit and a PHP webshell across Windows drivers and Roundcube webmail servers.

    1602162.9K
    44.0K followersView on X
  • Dark Web Informer@DarkWebInformer
    Disclosure

    ‼️ CISA has added 2 Roundcube vulns to the KEV catalog CVE-2025-68461: RoundCube Webmail Cross-site Scripting Vulnerability: RoundCube Webmail contains a cross-site scripting vulnerability via the animate tag in an SVG document. CVE-2025-49113: RoundCube Webmail Deserialization of Untrusted Data Vulnerability: RoundCube Webmail contains a deserialization of untrusted data vulnerability that allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php.

    Post summary

    The notice announces that CISA has added two RoundCube Webmail vulnerabilities to the KEV catalog, detailing their exploitation vectors and impact without mentioning exploits, patches, or active attacks.

    1701783.1K
    162.4K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    @proofpoint The mailbox was only the entry point. IceCube used the victim’s Roundcube session and CSRF token to exploit CVE-2025-49113, a post-authenticated RCE flaw. That gave attackers a path to deploy SquareShell in memory or use VShell for further access. https://t.co/IfN1Zk5qtV

    Post summary

    CVE‑2025‑49113 is being actively exploited by IceCube through a Roundcube CSRF-based post‑authenticated RCE, after which the attacker can deploy SquareShell or VShell for further access.

    1702047.6K
    2.3M followersView on X
  • FearsOff Cybersecurity@FearsOff
    Active Exploitation

    North Korea used servers vulnerable to a bug we found as C2 in its latest campaign targeting the defence, aerospace, and aviation sectors. Check Point's report last week: Lazarus exploited a Windows kernel zero-day, CVE-2026-68820 in afd.sys, since at least early July against defense, aerospace and aviation targets in France, Germany, Brazil and India. The campaign ran two parallel infection chains. One used signed-binary DLL sideloading to execute MISTPEN in memory. The other used a trojanized PDF viewer to deploy a new backdoor, Troy. Both could escalate to SYSTEM through CVE-2026-68820, followed by a new FudModule build designed to disable EDR visibility. MISTPEN ultimately deployed ForestTiger for long-term access. Microsoft patched the zero-day on 11 August. Much of the C2 infrastructure wasn't theirs. Check Point found compromised Roundcube, WordPress and PrestaShop servers being used as relay infrastructure. It assesses that Lazarus likely authenticated to vulnerable Roundcube servers using leaked credentials, exploited CVE-2025-49113, and planted RelayShell. The researchers identified at least 17 likely relay nodes. One compromised organization headquartered in France was then used to spear-phish targets worldwide - borrowing a legitimate organization's infrastructure and reputation to make the messages more credible. CVE-2025-49113 is ours. Our co-founder @k_firsov discovered and reported it in May 2025: authenticated RCE via PHP object deserialization, CVSS 9.9, sitting in the Roundcube codebase for more than a decade. Roundcube patched it on 1 June 2025. Attackers diffed and weaponized the vulnerability within 48 hours of the patch becoming available, with a working exploit offered for sale days later. We published the full technical breakdown to give defenders parity. CISA added CVE-2025-49113 to its Known Exploited Vulnerabilities catalog in February 2026, with a 13 March remediation deadline for covered US federal agencies. And Lazarus was still exploiting unpatched Roundcube servers in this campaign. We know the tradecraft because we spend our year on the other end of it. Lazarus is heavily involved in cryptocurrency theft, and we run continuous adversarial simulation against exchanges and protocols that sit high on the DPRK targeting list. The objectives differ, but the tradecraft overlaps: recruitment lures, signed-binary sideloading, credential theft, and kernel-level evasion. Theft there. Espionage here. If you build aircraft, satellites, drones, avionics, sensors or related defense technology, your engineers fit the targeting profile. And your internet-facing Roundcube, WordPress or PrestaShop infrastructure can become someone else's C2 if it isn't secured and patched. We find the bugs that might end up in campaigns like this one. We also run the campaign against our own clients first, on purpose, with a scope document. Our research: https://lnkd.in/dzS-RYcz

    Post summary

    The post reports confirmed, active exploitation of CVE‑2025‑49113 and CVE‑2026‑68820 by Lazarus for North Korean operations, highlights functional exploit methods, and underscores recently applied patches, providing a comprehensive view of the threat landscape.

    13072645
    2.1K followersView on X
  • Anonymous. Saints@Saints16294225
    Active Exploitation

    CISA KEV: Roundcube webmail flaws CVE-2025-49113 (9.9 RCE) & CVE-2025-68461 (XSS) actively exploited Authenticated attackers can execute code #OpChildSafe: Patch Roundcube IMMEDIATELY Weak email =open door for ransomware & data theft Protect the vulnerable 🕊️🔥 #ZeroDay #PatchNow https://t.co/tlGuJjZnfK

    Post summary

    CISA KEV reports that Roundcube webmail vulnerabilities CVE-2025-49113 (RCE) and CVE-2025-68461 (XSS) are actively exploited, urging users to patch immediately to prevent ransomware and data theft.

    05080446
    3.0K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    Active Exploitation

    🔴 Çin bağlantılı siber sadırganlar, kritik Roundcube güvenlik açıklarını kullanarak ABD ve Kanada'daki üniversiteleri hedef aldı! Zincirleme saldırıda CVE-2024-42009 ve CVE-2025-49113 istismar edilerek yalnızca e-postanın görüntülenmesiyle başlayan süreç, mail sunucusunun ele geçirilmesine kadar gidebiliyor. Yani zararlı e-postanın Roundcube'da açılmasıyla kimlik bilgileri çalınabiliyor ve mail sunucusunda uzaktan kod çalıştırılabiliyor. Teknik olarak bu risk sadece bu ülkelerle sınırlı değil. Türkiye lokasyon sunucularda da Roundcube versiyonu eski olan / yamalanmamış olan sunucular için de benzer saldırılar düzenlendiği biliniyor. Eğer Roundcube sürümü sunucunuzda eskiyse, acilen en yeni sürüme güncellemelisiniz.

    Post summary

    Chinese-linked attackers are actively exploiting CVE‑2024‑42009 and CVE‑2025‑49113 against Roundcube installations, enabling remote code execution after a malicious email is opened. Immediate patching of outdated Roundcube versions is urged.

    021721.6K
    2.2K followersView on X
  • Crowdfense@crowdfense
    Disclosure

    The following vulnerabilities have been added to our feed: - CVE-2025-49113: Roundcube PHP Object Deserialization RCE - CVE-2025-52691: SmarterMail Arbitrary File Upload RCE - CVE-2026-23760: SmarterMail Authentication Bypass RCE https://www.crowdfense.com/n-day-feed/

    Post summary

    The feed announces three newly added CVEs, each with a brief technical description, and provides a link to the source feed.

    11055772
    2.9K followersView on X
  • Olajeedae Jr 🇳🇬@r007User
    PoC

    Roundcube runs in more corporate mail servers than people think. CVE-2025-49113 hits upload.php via insecure deserialization. Get valid creds, run the script, shell on a live mail server. That simple. Full breakdown in the video 👇 https://youtu.be/o3t5nelswZY

    Post summary

    The post highlights CVE‑2025‑49113 against Roundcube’s upload.php, describing insecure deserialization that enables credential theft and shell access, and links to a video likely containing a proof‑of‑concept.

    00044606
    1.4K followersView on X
  • Ctrl-Alt-Intel@ctrlaltintel
    Active Exploitation

    Case 3: A threat actor attempted to exploit Roundcube CVE-2025-49113 against Kyrgyz National Security Service (https://mail.gknb.gov.kg) Other known CVEs and public POCs were used by this threat actor to target Found via 89.124.123[.]216:8080 - @Huntio Link to full article 👇 https://t.co/IRSs9FszS0

    Post summary

    The tweet reports an observed exploitation attempt targeting CVE-2025-49113 in Roundcube against a government entity (Kyrgyz National Security Service), noting the actor leveraged other public PoCs during the campaign.

    10041292
    1.4K followersView on X
  • DFIR Radar@DFIR_Radar
    Exploit

    North Korea 🇰🇵's Lazarus group deployed a Windows kernel zero-day via a post-quantum encrypted channel against defense and aerospace firms in France 🇫🇷, Germany 🇩🇪, Brazil 🇧🇷, and India 🇮🇳, with a patch shipping August 11. - CVE-2026-68820 is a use-after-free race condition in AFD.sys, the Windows kernel socket driver, flagged by Microsoft as actively exploited in the wild. Check Point reported it July 28; the patch landed August 12 Patch Tuesday. Prioritize this one. - The exploit arrived through a layered crypto handshake: MISTPEN (an in-memory downloader using Microsoft Graph API and attacker-controlled OneDrive files for C2) loaded a fingerprinting module that negotiated Kyber/ML-KEM key exchange with the operator, then decrypted the payload in memory over GOST-CBC on top of AES. No exploit touches disk. - What landed was FudModule v3.1, Lazarus's kernel rootkit. It kills 94 ETW providers, removes minifilters, disables telemetry callbacks, wipes the NT Kernel Logger, and now tampers with Smart App Control by resetting policy state and forcing a code integrity reload. - Infrastructure ran through compromised Roundcube servers (CVE-2025-49113) and PrestaShop sites hosting RelayShell, a new PHP webshell passing traffic via session files across at least 17 relay servers. Three fake Enveil sites distributed Troy, a new backdoor with 17 operator commands, via a trojanized PDF viewer. Patch AFD.sys immediately. #DFIR_Radar

    Post summary

    CVE-2026-68820, a use‑after‑free in Windows AFD.sys, has been actively exploited by Lazarus with the FudModule v3.1 kernel rootkit delivered via MISTPEN. A patch is available as of August 12, and the operation leveraged post‑quantum cryptography and compromised infrastructure.

    30020368
    2.0K followersView on X
  • CCB Alert@CCBalert
    Active Exploitation

    Warning: Critical PHP deserialization flaw in #Roundcube Webmail. #CVE-2025-49113 CVSS: 9.9. Authenticated users can trigger #RCE via crafted requests. Actively exploited by ransomware groups. #Patch #Patch #Patch More info: https://ccb.belgium.be/advisories/warning-critical-php-deserialization-vulnerability-roundcube-webmail-patch-immediately

    Post summary

    Critical PHP deserialization flaw (CVE‑2025‑49113) in Roundcube Webmail, rated CVSS 9.9, is actively exploited by ransomware groups; immediate patching is advised.

    02021331
    7.2K followersView on X
  • Modat@modat_magnify
    Active Exploitation

    CVE-2025-49113 / CVE-2025-68461  ⚠️ Roundcube Webmail – Actively Exploited RCE & XSS (CISA KEV)  CISA has added CVE-2025-49113 and CVE-2025-68461 to its KEV catalogue following confirmation of active in-the-wild exploitation targeting Roundcube Webmail.  CVE-2025-49113 (CVSS 9.9) is a deserialization vulnerability that allows authenticated attackers to achieve remote code execution via improper validation of the _from parameter.  CVE-2025-68461 is a cross-site scripting flaw exploitable through the SVG animate tag, enabling malicious script execution.  Patch immediately (1.6.12 / 1.5.12+).  Modat Magnify Query: 
web.title~"Roundcube Webmail"  The platform: 
https://magnify.modat.io/  #threatintel #vulnerability #CVE202549113 #CVE202568461 #Roundcube #RCE #XSS #CISA #KEV #infosec #ModatMagnify

    Post summary

    CISA confirms active exploitation of two Roundcube Webmail CVEs—CVE‑2025‑49113 (RCE) and CVE‑2025‑68461 (XSS). Patches are available immediately.

    01022173
    290 followersView on X
  • Canadian Centre for Cyber Security@cybercentre_ca
    General

    #CyberAlert | Update: Roundcube Webmail vulnerabilities CVE-2024-42009 and CVE-2025-49113 https://www.cyber.gc.ca/en/alerts-advisories/vulnerability-impacting-roundcube-webmail-cve-2025-49113 https://t.co/fyi0kpLXFO

    Post summary

    The tweet merely announces Roundcube Webmail vulnerabilities and links to an external alert, offering no specific technical or exploit information.

    01030737
    34.0K followersView on X
  • PurpleOps@PurpleOps_io
    Active Exploitation

    a china-aligned crew (UNK_MassTraction) is quietly exploiting two roundcube webmail bugs, CVE-2024-42009 and CVE-2025-49113, to get into US and canadian university mail servers. the targeting is the tell: physics and engineering departments, the research inboxes. this is espionage via webmail, not smash-and-grab. running since may.

    Post summary

    The post reports that the China‑aligned crew UNK_MassTraction is actively exploiting two Roundcube webmail bugs (CVE-2024-42009 and CVE-2025-49113) against U.S. and Canadian university mail servers, targeting physics and engineering research inboxes since May.

    11020168
    608 followersView on X
  • Threat Landscape@LandscapeThreat

    Roundcube webmail servers are now an exploitation target. CVE-2026-48842 is a pre-authentication SQL injection in the virtuser_query plugin. Specially crafted backslash sequences can bypass escaping and inject SQL without authentication. The Canadian Centre for Cyber Security reported active exploitation based on open-source reporting. Roundcube 1.6.x before 1.6.16 and 1.7.x before 1.7.1 are affected. Fixes shipped May 24, 2026. Successful exploitation could expose database contents, including mailbox credentials and stored messages, depending on database permissions and configuration. The report lists actor UNK_MassTraction and malware VShell, but provides no reliable IOCs or attribution. Its vulnerability set also includes CVE-2025-68461 and CVE-2025-49113. Treat this as OSINT: verify exposure and patch affected systems. Get the dossier on our platform, ATT&CK-mapped, sourced and exportable.

    0002048
    96 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSdebiandebian_linux11.0--
Approundcubewebmail---

Explore more