CVE-2025-68461Active Exploitation(roundcube / webmail)

HIGHCVSS 6.1 · MEDIUMCISA KEV

Exploitation observed; activity peaked at 12 mentions and remains active

Immediate actions

  • Patch roundcube webmail systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: Immediate (within 24h)

NVD description

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.

6.3/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-03-13. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-79

Priority

HIGH

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • webmail

Threat summary

  • Active exploitation appears in 27 classified signals
  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 36 mentions across 9 observed days

What's happening

  • Active exploitation reported across 27 signals
  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 12 signals
  • Technical details provided in 14 signals
  • Disclosure: 5 classified signals
  • General: 3 classified signals
  • Peaked 4d ago at 12 mentions (2026-02-25); latest day: 1
  • 36 total mentions across 9 days

Affected systems

Vendors
Products
webmail

Deep dive

Activity timeline36 mentions / 9d
036912Mentions · 2026-02-20: 3Mentions · 2026-02-21: 1Mentions · 2026-02-23: 8Mentions · 2026-02-24: 5Mentions · 2026-02-25: 12Mentions · 2026-02-26: 4Mentions · 2026-03-12: 1Mentions · 2026-03-18: 1Mentions · 2026-09-30: 1Exploit Tool / Code · 2026-02-23: 1Active Exploitation · 2026-02-20: 2Active Exploitation · 2026-02-23: 8Active Exploitation · 2026-02-24: 3Active Exploitation · 2026-02-25: 11Active Exploitation · 2026-02-26: 3Patch / Workaround · 2026-02-20: 1Patch / Workaround · 2026-02-23: 6Patch / Workaround · 2026-02-24: 3Patch / Workaround · 2026-02-25: 1Patch / Workaround · 2026-03-18: 1Technical Details · 2026-02-20: 1Technical Details · 2026-02-21: 1Technical Details · 2026-02-23: 6Technical Details · 2026-02-24: 4Technical Details · 2026-02-25: 1Technical Details · 2026-03-18: 102-2002-2102-2302-2402-2502-2603-1203-1809-30
Signal classification3 categories
Active Exploitation
2777.1%
Disclosure
514.3%
General
38.6%
Referenced assets21 URLs
Classification over time
DateTotalLabels
2026-02-203
Active Exploitation2Disclosure1
2026-02-211
Disclosure1
2026-02-238
Active Exploitation8
2026-02-245
Active Exploitation3Disclosure1General1
2026-02-2512
Active Exploitation11General1
2026-02-264
Active Exploitation3Disclosure1
2026-03-121
General1
2026-03-181
Disclosure1
Full discourse20 posts
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️ We added RoundCube Webmail vulnerabilities CVE-2025-49113 & CVE-2025-68461 to our Known Exploited Vulnerabilities Catalog. Visit https://go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/94NN54MXCA

    Post summary

    DHS reports that RoundCube Webmail CVE‑2025‑49113 and CVE‑2025‑68461 are actively exploited and recommends applying mitigations.

    41003343.6K
    291.5K followersView on X
  • Dark Web Informer@DarkWebInformer
    Active Exploitation

    ‼️ CISA has added 2 Roundcube vulns to the KEV catalog CVE-2025-68461: RoundCube Webmail Cross-site Scripting Vulnerability: RoundCube Webmail contains a cross-site scripting vulnerability via the animate tag in an SVG document. CVE-2025-49113: RoundCube Webmail Deserialization of Untrusted Data Vulnerability: RoundCube Webmail contains a deserialization of untrusted data vulnerability that allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php.

    Post summary

    CISA listed two RoundCube Webmail vulnerabilities in its KEV catalog, indicating active exploitation, with explicit details of XSS and RCE vectors.

    1701783.1K
    162.4K followersView on X
  • Anonymous. Saints@Saints16294225
    Active Exploitation

    CISA KEV: Roundcube webmail flaws CVE-2025-49113 (9.9 RCE) & CVE-2025-68461 (XSS) actively exploited Authenticated attackers can execute code #OpChildSafe: Patch Roundcube IMMEDIATELY Weak email =open door for ransomware & data theft Protect the vulnerable 🕊️🔥 #ZeroDay #PatchNow https://t.co/tlGuJjZnfK

    Post summary

    CISA identifies Roundcube webmail vulnerabilities CVE‑2025‑49113 (RCE) and CVE‑2025‑68461 (XSS) as actively exploited, urging immediate patching to prevent ransomware and data theft.

    05080446
    3.0K followersView on X
  • Ostorlab@OstorlabSec
    Disclosure

    CVE-2025-68461: Roundcube Webmail SVG <animate> XSS sanitizer bypass (CVSS 7.2 High). Affects <1.5.12 and <1.6.12. Trick: attributeName="xlink:href" slips past naive comparisons → stored XSS path. Fix: normalize/strip namespace prefix. https://blog.ostorlab.co/cve-2025-68461-xss-roundcube.html #XSS #CVE #Roundcube #AppSec

    Post summary

    The post announces CVE-2025-68461, detailing its XSS nature, affected Roundcube versions, exploitation method, and the recommended fix to normalize or strip namespace prefixes.

    02030137
    589 followersView on X
  • Modat@modat_magnify
    Active Exploitation

    CVE-2025-49113 / CVE-2025-68461  ⚠️ Roundcube Webmail – Actively Exploited RCE & XSS (CISA KEV)  CISA has added CVE-2025-49113 and CVE-2025-68461 to its KEV catalogue following confirmation of active in-the-wild exploitation targeting Roundcube Webmail.  CVE-2025-49113 (CVSS 9.9) is a deserialization vulnerability that allows authenticated attackers to achieve remote code execution via improper validation of the _from parameter.  CVE-2025-68461 is a cross-site scripting flaw exploitable through the SVG animate tag, enabling malicious script execution.  Patch immediately (1.6.12 / 1.5.12+).  Modat Magnify Query: 
web.title~"Roundcube Webmail"  The platform: 
https://magnify.modat.io/  #threatintel #vulnerability #CVE202549113 #CVE202568461 #Roundcube #RCE #XSS #CISA #KEV #infosec #ModatMagnify

    Post summary

    CISA has confirmed active in‑the‑wild exploitation of two Roundcube Webmail CVEs, with high‑severity RCE and XSS flaws, and urges immediate patching to versions 1.6.12 or 1.5.12+.

    01022173
    290 followersView on X
  • Threat Landscape@LandscapeThreat

    Roundcube webmail servers are now an exploitation target. CVE-2026-48842 is a pre-authentication SQL injection in the virtuser_query plugin. Specially crafted backslash sequences can bypass escaping and inject SQL without authentication. The Canadian Centre for Cyber Security reported active exploitation based on open-source reporting. Roundcube 1.6.x before 1.6.16 and 1.7.x before 1.7.1 are affected. Fixes shipped May 24, 2026. Successful exploitation could expose database contents, including mailbox credentials and stored messages, depending on database permissions and configuration. The report lists actor UNK_MassTraction and malware VShell, but provides no reliable IOCs or attribution. Its vulnerability set also includes CVE-2025-68461 and CVE-2025-49113. Treat this as OSINT: verify exposure and patch affected systems. Get the dossier on our platform, ATT&CK-mapped, sourced and exportable.

    0002048
    96 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Active Exploitation

    Roundcube vulnerabilities (CVE-2025-49113, CVE-2025-68461) and BeyondTrust CVE-2026-1731 exploited in ransomware attacks delivering SparkRAT and VShell. PayPal and FICOBA breaches affect millions. AI and quantum security make progress. #BeyondTrust #PayPal https://ift.tt/YDoOsdm

    Post summary

    The post reports that Roundcube and BeyondTrust CVEs are being actively exploited in ransomware campaigns using SparkRAT and VShell, affecting millions of users.

    00020178
    3.6K followersView on X
  • Alone@alodotne
    General

    @the_real_egg_f @ProtonMail I'm confused? A webmail client is better than the actual email service it self?! CVE-2025-68461 CVE-2025-49113 CVE-2025-68460 CVE-2024-42009 CVE-2024-37385 CVE-2023-5631 CVE-2021-44026 CVE-2020-12641 CVE-2017-16651

    Post summary

    The tweet merely lists several CVE identifiers without providing any additional technical, exploit, or mitigation information.

    10000174
    54 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Active Exploitation

    CISA alerts on active exploits of patched Roundcube Webmail flaws CVE-2025-49113 &amp; CVE-2025-68461 tied to Winter Vivern and APT28. New AI-assisted Arkanix Stealer targets browsers, wallets, and games. #WinterVivern #ArkanixStealer #USA https://ift.tt/O1uTbGU

    Post summary

    CISA reports that Roundcube Webmail vulnerabilities CVE-2025-49113 and CVE-2025-68461 are being actively exploited by Winter Vivern and APT28, despite patches being available.

    00010179
    3.7K followersView on X
  • transilienceai@transilienceai
    Disclosure

    @Dread91400105 **CVE-2025-68461** is a **cross-site scripting (XSS) vulnerability** in Roundcube Webmail that allows remote, unauthenticated attackers to execute malicious scripts through the animate tag in SVG documents. ⚠️ #CyberSecurity #XSS

    Post summary

    The post announces CVE-2025-68461 as an XSS flaw in Roundcube Webmail that allows unauthenticated attackers to execute scripts via the animate tag in SVG documents.

    1000056
    319 followersView on X
  • キタきつね@foxbook
    General

    CISAが2つの既知の脆弱性をカタログに追加 CISA Adds Two Known Exploited Vulnerabilities to Catalog #CISA (Feb 20) CVE-2025-49113 RoundCube Webメールにおける信頼できないデータのデシリアライゼーションの脆弱性 CVE-2025-68461 RoundCube Webメールのクロスサイトスクリプティング脆弱性 https://www.cisa.gov/news-events/alerts/2026/02/20/cisa-adds-two-known-exploited-vulnerabilities-catalog

    Post summary

    CISA announced adding two known exploited vulnerabilities (CVE-2025-49113 and CVE-2025-68461) to its catalog, but no further details on exploitation, patches, or PoC were provided.

    00010236
    4.7K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Active Exploitation

    CISA reports active exploits targeting Roundcube Webmail flaws CVE-2025-49113 and CVE-2025-68461, with over 84,000 exposed instances. Federal agencies must patch by March 13 under BOD 22-01. #RoundcubeFlaws #U.S. #APT28 https://ift.tt/21C5rQz

    Post summary

    CISA confirms active exploitation of Roundcube Webmail CVEs CVE-2025-49113 and CVE-2025-68461, urging federal agencies to patch by March 13.

    00010143
    3.6K followersView on X
  • サイバーセキュリティニュース-JP@cybersecnews_jp
    Disclosure

    CISAが2つの既知の脆弱性をカタログに追加 https://www.cisa.gov/news-events/alerts/2026/02/20/cisa-adds-two-known-exploited-vulnerabilities-catalog CVE-2025-49113 RoundCube Webメールにおける信頼できないデータのデシリアライゼーションの脆弱性 CVE-2025-68461 RoundCube Webメールのクロスサイトスクリプティング脆弱性

    Post summary

    CISA has listed two CVEs for RoundCube Web Mail, describing them as deserialization and XSS vulnerabilities, without providing any PoC, exploit details, patch information or evidence of active exploitation.

    1000063
    45 followersView on X
  • mysocAi@MysocAi
    Disclosure

    [CRITICAL] CVE-2025-49113 and CVE-2025-68461 Added to CISA KEV Catalog CISA adds CVE-2025-49113 and CVE-2025-68461 to KEV Catalog; federal agencies must remediate by March 13, 2026. CVE: CVE-2025-49113, CVE… https://ankura.com/insights/ankura-ctix-flash-update-february-24-2026/

    Post summary

    CISA has added CVE-2025-49113 and CVE-2025-68461 to its KEV catalog, requiring federal agencies to remediate by March 13, 2026.

    000003
    3 followersView on X
  • mysocAi@MysocAi
    Active Exploitation

    [CRITICAL] CISA Adds Critical Roundcube Vulnerabilities to KEV Catalog CISA added CVE-2025-49113 and CVE-2025-68461 to KEV Catalog due to active exploitation. CVE: CVE-2025-49113, CVE-2025-68461 • APT: N/A … https://ankura.com/insights/ankura-ctix-flash-update-february-24-2026/

    Post summary

    CISA has added CVE-2025-49113 and CVE-2025-68461 to the KEV catalog, citing active exploitation in the wild.

    000002
    3 followersView on X
  • mysocAi@MysocAi
    Active Exploitation

    [HIGH] CISA Adds CVE-2025-49113 and CVE-2025-68461 to KEV Catalog CISA added two Roundcube Webmail vulnerabilities to KEV Catalog due to active exploitation. CVE: CVE-2025-49113, CVE-2025-68461 • APT: Unkno… https://ankura.com/insights/ankura-ctix-flash-update-february-24-2026/

    Post summary

    CISA has added CVE-2025-49113 and CVE-2025-68461 to the KEV catalog, citing active exploitation of Roundcube Webmail vulnerabilities.

    000003
    3 followersView on X
  • mysocAi@MysocAi
    Active Exploitation

    [CRITICAL] CISA Adds CVE-2025-68461 to KEV Catalog CISA adds CVE-2025-68461 to KEV Catalog; agencies must remediate by March 13. CVE: CVE-2025-68461 • APT: N/A • Status: ACTIVE Federal agencies must act by… https://ankura.com/insights/ankura-ctix-flash-update-february-24-2026/

    Post summary

    CISA has added CVE-2025-68461 to its KEV catalog, indicating that the vulnerability is actively exploited and federal agencies must remediate by March 13.

    000002
    3 followersView on X
  • mysocAi@MysocAi
    Active Exploitation

    [HIGH] CISA Adds RoundCube Webmail Vulnerabilities to KEV List CVE-2025-49113 and CVE-2025-68461 in RoundCube Webmail pose significant risks. CVE: CVE-2025-49113, CVE-2025-68461 • APT: APT28 • Status… https://www.haleconsultingsolutions.com/post/hale-insights---february-23-2026

    Post summary

    CISA has added two RoundCube Webmail CVEs (CVE-2025-49113 and CVE-2025-68461) to its KEV list, indicating they are actively exploited in the wild.

    000000
    3 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Roundcube ❗ CVE-2025-68461 ❗ CVE-2025-68460 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-roundcube/ https://t.co/aeSWzDBAoR

    Post summary

    The post lists two CVE identifiers for Roundcube vulnerabilities but offers no further technical or remedial information.

    00000117
    6.6K followersView on X
  • mysocAi@MysocAi
    Active Exploitation

    [HIGH] RoundCube Webmail Vulnerabilities Added to KEV List CISA adds two RoundCube flaws to its Known Exploited Vulnerabilities list. CVE: CVE-2025-49113, CVE-2025-68461 • APT: APT28 • Status: ACTIVE… https://www.haleconsultingsolutions.com/post/hale-insights---february-23-2026

    Post summary

    CISA has added two RoundCube Webmail vulnerabilities (CVE-2025-49113 and CVE-2025-68461) to its Known Exploited Vulnerabilities list, indicating active exploitation by APT28.

    000000
    3 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Approundcubewebmail---

Explore more