Ostorlab[verified]@OstorlabSecDisclosure
The post announces CVE-2025-68461, detailing its XSS nature, affected Roundcube versions, exploitation method, and the recommended fix to normalize or strip namespace prefixes.
Modat[verified]@modat_magnifyActive Exploitation
CISA has confirmed active in‑the‑wild exploitation of two Roundcube Webmail CVEs, with high‑severity RCE and XSS flaws, and urges immediate patching to versions 1.6.12 or 1.5.12+.
transilienceai[verified]@transilienceaiDisclosure
The post announces CVE-2025-68461 as an XSS flaw in Roundcube Webmail that allows unauthenticated attackers to execute scripts via the animate tag in SVG documents.
キタきつね[verified]@foxbookGeneral
CISA announced adding two known exploited vulnerabilities (CVE-2025-49113 and CVE-2025-68461) to its catalog, but no further details on exploitation, patches, or PoC were provided.
mysocAi[verified]@MysocAiDisclosure
CISA has added CVE-2025-49113 and CVE-2025-68461 to its KEV catalog, requiring federal agencies to remediate by March 13, 2026.
mysocAi[verified]@MysocAiActive Exploitation
CISA has added CVE-2025-49113 and CVE-2025-68461 to the KEV catalog, citing active exploitation in the wild.
mysocAi[verified]@MysocAiActive Exploitation
CISA has added CVE-2025-49113 and CVE-2025-68461 to the KEV catalog, citing active exploitation of Roundcube Webmail vulnerabilities.
mysocAi[verified]@MysocAiActive Exploitation
CISA has added CVE-2025-68461 to its KEV catalog, indicating that the vulnerability is actively exploited and federal agencies must remediate by March 13.