Exploitation observed; activity peaked at 11 mentions and remains active
Immediate actions
Patch debian debian_linux systems immediately
Assume compromise if assets are exposed
Hunt for exploitation attempts and persistence artifacts
Increase monitoring for publicly documented tradecraft
Recommended action window: Immediate (within 24h)
NVD description
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.
Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-03-13. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
0-Day Used by Lazarus in #DreamJob Campaign Against Defense Sector:
💥LPE vulnerability in Microsoft’s Afd.sys driver (CVE-2026-68820)
🧰New tools, including #Troy backdoor
🌍Compromised Roundcube servers (CVE-2025-49113) as infrastructure
Read More :
https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/ https://t.co/MIGKtH6FlM
Post summary
The Lazarus group reportedly exploited a zero‑day LPE in Microsoft’s Afd.sys (CVE‑2026‑68820) against defense targets, deploying new tools including the #Troy backdoor and leveraging compromised Roundcube servers.
Your email server might be vulnerable! CVE-2025-49113 allows attackers to compromise servers without authentication.
https://hackers-arise.com/critical-remote-code-execution-rce-in-roundcube-cve-2025-49113-your-email-is-not-safe/
@three_cube@DI0256@IamSmouk@co11ateral https://t.co/a9gyDen9o4
Post summary
The post announces the existence of CVE‑2025‑49113, a remote code execution flaw in Roundcube that permits unauthenticated exploitation, and directs readers to an external article for more information.
🚨 Suspected China-aligned UNK_MassTraction exploited now-patched Roundcube flaws against U.S. and Canadian university departments.
IceCube stole credentials, 2FA data, and cookies, then used CVE-2025-49113 to drop VShell or a web shell.
How the mail server compromise worked: https://thehackernews.com/2026/07/suspected-china-aligned-hackers-exploit.html
Post summary
Suspected China-aligned group exploited a recently patched Roundcube CVE, stealing credentials and dropping web shells, with a reference to a news article for more detail.
🛡️ We added RoundCube Webmail vulnerabilities CVE-2025-49113 & CVE-2025-68461 to our Known Exploited Vulnerabilities Catalog. Visit https://go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity#InfoSec https://t.co/94NN54MXCA
Post summary
DHS lists two RoundCube Webmail CVEs as known exploited and advises applying mitigations, indicating confirmed real‑world use.
Operation Dream Job
#Lazarus exploited CVE-2026-68820, a zero-day vulnerability in the Microsoft AFD.sys driver, to deploy a new version of FudModule, Lazarus’ kernel-mode rootkit.
https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/
Lazarus also used CVE-2025-49113 to exploit vulnerable Roundcube webmail servers. The compromised servers were infected with RelayShell, a PHP webshell that repurposes compromised web servers as relay nodes within the attacker’s command-and-control infrastructure.
Post summary
The post reports Lazarus actively exploiting CVE‑2026‑68820 and CVE‑2025‑49113 to deploy a kernel‑mode rootkit and a PHP webshell across Windows drivers and Roundcube webmail servers.
‼️ CISA has added 2 Roundcube vulns to the KEV catalog
CVE-2025-68461: RoundCube Webmail Cross-site Scripting Vulnerability: RoundCube Webmail contains a cross-site scripting vulnerability via the animate tag in an SVG document.
CVE-2025-49113: RoundCube Webmail Deserialization of Untrusted Data Vulnerability: RoundCube Webmail contains a deserialization of untrusted data vulnerability that allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php.
Post summary
The notice announces that CISA has added two RoundCube Webmail vulnerabilities to the KEV catalog, detailing their exploitation vectors and impact without mentioning exploits, patches, or active attacks.
@proofpoint The mailbox was only the entry point.
IceCube used the victim’s Roundcube session and CSRF token to exploit CVE-2025-49113, a post-authenticated RCE flaw.
That gave attackers a path to deploy SquareShell in memory or use VShell for further access. https://t.co/IfN1Zk5qtV
Post summary
CVE‑2025‑49113 is being actively exploited by IceCube through a Roundcube CSRF-based post‑authenticated RCE, after which the attacker can deploy SquareShell or VShell for further access.
North Korea used servers vulnerable to a bug we found as C2 in its latest campaign targeting the defence, aerospace, and aviation sectors.
Check Point's report last week: Lazarus exploited a Windows kernel zero-day, CVE-2026-68820 in afd.sys, since at least early July against defense, aerospace and aviation targets in France, Germany, Brazil and India.
The campaign ran two parallel infection chains. One used signed-binary DLL sideloading to execute MISTPEN in memory. The other used a trojanized PDF viewer to deploy a new backdoor, Troy. Both could escalate to SYSTEM through CVE-2026-68820, followed by a new FudModule build designed to disable EDR visibility. MISTPEN ultimately deployed ForestTiger for long-term access.
Microsoft patched the zero-day on 11 August.
Much of the C2 infrastructure wasn't theirs.
Check Point found compromised Roundcube, WordPress and PrestaShop servers being used as relay infrastructure. It assesses that Lazarus likely authenticated to vulnerable Roundcube servers using leaked credentials, exploited CVE-2025-49113, and planted RelayShell.
The researchers identified at least 17 likely relay nodes.
One compromised organization headquartered in France was then used to spear-phish targets worldwide - borrowing a legitimate organization's infrastructure and reputation to make the messages more credible.
CVE-2025-49113 is ours.
Our co-founder @k_firsov discovered and reported it in May 2025: authenticated RCE via PHP object deserialization, CVSS 9.9, sitting in the Roundcube codebase for more than a decade.
Roundcube patched it on 1 June 2025.
Attackers diffed and weaponized the vulnerability within 48 hours of the patch becoming available, with a working exploit offered for sale days later. We published the full technical breakdown to give defenders parity.
CISA added CVE-2025-49113 to its Known Exploited Vulnerabilities catalog in February 2026, with a 13 March remediation deadline for covered US federal agencies.
And Lazarus was still exploiting unpatched Roundcube servers in this campaign.
We know the tradecraft because we spend our year on the other end of it.
Lazarus is heavily involved in cryptocurrency theft, and we run continuous adversarial simulation against exchanges and protocols that sit high on the DPRK targeting list.
The objectives differ, but the tradecraft overlaps: recruitment lures, signed-binary sideloading, credential theft, and kernel-level evasion.
Theft there. Espionage here.
If you build aircraft, satellites, drones, avionics, sensors or related defense technology, your engineers fit the targeting profile.
And your internet-facing Roundcube, WordPress or PrestaShop infrastructure can become someone else's C2 if it isn't secured and patched.
We find the bugs that might end up in campaigns like this one.
We also run the campaign against our own clients first, on purpose, with a scope document.
Our research: https://lnkd.in/dzS-RYcz
Post summary
The post reports confirmed, active exploitation of CVE‑2025‑49113 and CVE‑2026‑68820 by Lazarus for North Korean operations, highlights functional exploit methods, and underscores recently applied patches, providing a comprehensive view of the threat landscape.
CISA KEV: Roundcube webmail flaws CVE-2025-49113 (9.9 RCE) & CVE-2025-68461 (XSS) actively exploited
Authenticated attackers can execute code
#OpChildSafe: Patch Roundcube IMMEDIATELY
Weak email =open door for ransomware & data theft
Protect the vulnerable
🕊️🔥 #ZeroDay#PatchNow https://t.co/tlGuJjZnfK
Post summary
CISA KEV reports that Roundcube webmail vulnerabilities CVE-2025-49113 (RCE) and CVE-2025-68461 (XSS) are actively exploited, urging users to patch immediately to prevent ransomware and data theft.
🔴 Çin bağlantılı siber sadırganlar, kritik Roundcube güvenlik açıklarını kullanarak ABD ve Kanada'daki üniversiteleri hedef aldı!
Zincirleme saldırıda CVE-2024-42009 ve CVE-2025-49113 istismar edilerek yalnızca e-postanın görüntülenmesiyle başlayan süreç, mail sunucusunun ele geçirilmesine kadar gidebiliyor. Yani zararlı e-postanın Roundcube'da açılmasıyla kimlik bilgileri çalınabiliyor ve mail sunucusunda uzaktan kod çalıştırılabiliyor.
Teknik olarak bu risk sadece bu ülkelerle sınırlı değil. Türkiye lokasyon sunucularda da Roundcube versiyonu eski olan / yamalanmamış olan sunucular için de benzer saldırılar düzenlendiği biliniyor.
Eğer Roundcube sürümü sunucunuzda eskiyse, acilen en yeni sürüme güncellemelisiniz.
Post summary
Chinese-linked attackers are actively exploiting CVE‑2024‑42009 and CVE‑2025‑49113 against Roundcube installations, enabling remote code execution after a malicious email is opened. Immediate patching of outdated Roundcube versions is urged.
Roundcube runs in more corporate mail servers than people think.
CVE-2025-49113 hits upload.php via insecure deserialization. Get valid creds, run the script, shell on a live mail server. That simple.
Full breakdown in the video 👇
https://youtu.be/o3t5nelswZY
Post summary
The post highlights CVE‑2025‑49113 against Roundcube’s upload.php, describing insecure deserialization that enables credential theft and shell access, and links to a video likely containing a proof‑of‑concept.
Case 3: A threat actor attempted to exploit Roundcube CVE-2025-49113 against Kyrgyz National Security Service (https://mail.gknb.gov.kg)
Other known CVEs and public POCs were used by this threat actor to target
Found via 89.124.123[.]216:8080 - @Huntio
Link to full article 👇 https://t.co/IRSs9FszS0
Post summary
The tweet reports an observed exploitation attempt targeting CVE-2025-49113 in Roundcube against a government entity (Kyrgyz National Security Service), noting the actor leveraged other public PoCs during the campaign.
North Korea 🇰🇵's Lazarus group deployed a Windows kernel zero-day via a post-quantum encrypted channel against defense and aerospace firms in France 🇫🇷, Germany 🇩🇪, Brazil 🇧🇷, and India 🇮🇳, with a patch shipping August 11.
- CVE-2026-68820 is a use-after-free race condition in AFD.sys, the Windows kernel socket driver, flagged by Microsoft as actively exploited in the wild. Check Point reported it July 28; the patch landed August 12 Patch Tuesday. Prioritize this one.
- The exploit arrived through a layered crypto handshake: MISTPEN (an in-memory downloader using Microsoft Graph API and attacker-controlled OneDrive files for C2) loaded a fingerprinting module that negotiated Kyber/ML-KEM key exchange with the operator, then decrypted the payload in memory over GOST-CBC on top of AES. No exploit touches disk.
- What landed was FudModule v3.1, Lazarus's kernel rootkit. It kills 94 ETW providers, removes minifilters, disables telemetry callbacks, wipes the NT Kernel Logger, and now tampers with Smart App Control by resetting policy state and forcing a code integrity reload.
- Infrastructure ran through compromised Roundcube servers (CVE-2025-49113) and PrestaShop sites hosting RelayShell, a new PHP webshell passing traffic via session files across at least 17 relay servers. Three fake Enveil sites distributed Troy, a new backdoor with 17 operator commands, via a trojanized PDF viewer.
Patch AFD.sys immediately.
#DFIR_Radar
Post summary
CVE-2026-68820, a use‑after‑free in Windows AFD.sys, has been actively exploited by Lazarus with the FudModule v3.1 kernel rootkit delivered via MISTPEN. A patch is available as of August 12, and the operation leveraged post‑quantum cryptography and compromised infrastructure.
CVE-2025-49113 / CVE-2025-68461
⚠️ Roundcube Webmail – Actively Exploited RCE & XSS (CISA KEV)
CISA has added CVE-2025-49113 and CVE-2025-68461 to its KEV catalogue following confirmation of active in-the-wild exploitation targeting Roundcube Webmail.
CVE-2025-49113 (CVSS 9.9) is a deserialization vulnerability that allows authenticated attackers to achieve remote code execution via improper validation of the _from parameter.
CVE-2025-68461 is a cross-site scripting flaw exploitable through the SVG animate tag, enabling malicious script execution.
Patch immediately (1.6.12 / 1.5.12+).
Modat Magnify Query: web.title~"Roundcube Webmail"
The platform: https://magnify.modat.io/
#threatintel#vulnerability#CVE202549113#CVE202568461#Roundcube#RCE#XSS#CISA#KEV#infosec#ModatMagnify
Post summary
CISA confirms active exploitation of two Roundcube Webmail CVEs—CVE‑2025‑49113 (RCE) and CVE‑2025‑68461 (XSS). Patches are available immediately.
a china-aligned crew (UNK_MassTraction) is quietly exploiting two roundcube webmail bugs, CVE-2024-42009 and CVE-2025-49113, to get into US and canadian university mail servers. the targeting is the tell: physics and engineering departments, the research inboxes. this is espionage via webmail, not smash-and-grab. running since may.
Post summary
The post reports that the China‑aligned crew UNK_MassTraction is actively exploiting two Roundcube webmail bugs (CVE-2024-42009 and CVE-2025-49113) against U.S. and Canadian university mail servers, targeting physics and engineering research inboxes since May.
Roundcube webmail servers are now an exploitation target.
CVE-2026-48842 is a pre-authentication SQL injection in the virtuser_query plugin. Specially crafted backslash sequences can bypass escaping and inject SQL without authentication.
The Canadian Centre for Cyber Security reported active exploitation based on open-source reporting. Roundcube 1.6.x before 1.6.16 and 1.7.x before 1.7.1 are affected. Fixes shipped May 24, 2026. Successful exploitation could expose database contents, including mailbox credentials and stored messages, depending on database permissions and configuration.
The report lists actor UNK_MassTraction and malware VShell, but provides no reliable IOCs or attribution. Its vulnerability set also includes CVE-2025-68461 and CVE-2025-49113. Treat this as OSINT: verify exposure and patch affected systems.
Get the dossier on our platform, ATT&CK-mapped, sourced and exportable.