CVE-2025-49113 — Roundcube Webmail
CISA KEVAs of 2026-02-23, CVE-2025-49113 is a CRITICAL-severity vulnerability in Roundcube Webmail, CVSS v3.1 9.9, EPSS 91.5% (99.6th percentile). It is listed in the CISA Known Exploited Vulnerabilities catalog (added 2026-02-20), with a US federal remediation deadline of 2026-03-13. Threadlinqs Intelligence links 4 tracked threat campaigns to CVE-2025-49113, most recently “Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820 (AFD.sys) and Two Publicly Disclosed Zero-Days (CVE-2026-62832 "LegacyHive", CVE-2026-72971)”.
Last updated: 2026-02-23
What is CVE-2025-49113?
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.
The record classifies CVE-2025-49113 under weakness class CWE-502. Its CVSS v3 base vector states that the flaw is reachable remotely over the network, needs low-privilege credentials, needs no user interaction, and has high impact on confidentiality, integrity, availability. 2 affected-product entries are recorded, across 2 vendors, listed below. The identifier was first published 468 days ago.
Severity and exploitation probability
- CVSS v3.1 base score
- 9.9 — CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H - EPSS (FIRST)
- 91.5% probability of exploitation in the next 30 days, higher than 99.6% of all scored CVEs
- CISA KEV
- Listed since 2026-02-20, federal remediation deadline 2026-03-13
- Threadlinqs priority
- 9/10 — CISA KEV-listed, which Threadlinqs floors at 9
- Published
- 2025-06-02, last modified 2026-02-23
Is CVE-2025-49113 being exploited?
CISA added CVE-2025-49113 to the Known Exploited Vulnerabilities catalog on 2026-02-20, which means the agency holds evidence of exploitation in the wild; US federal civilian agencies had to remediate it by 2026-03-13 under BOD 22-01. It currently carries a trending score of 40 in the Threadlinqs vulnerability feed.
Affected products and versions
- Roundcube: Webmail
- Debian: Linux 11.0
How to fix CVE-2025-49113
The record marks a vendor fix as available for CVE-2025-49113. Patch reference: https://github.com/roundcube/roundcubemail/commit/c50a07d88ca38f018a0f4a0b008e9a1deb32637e. Vendor advisory: https://github.com/roundcube/roundcubemail/commit/0376f69e958a8fef7f6f09e352c541b4e7729c4d. Because CVE-2025-49113 is KEV-listed, US federal civilian agencies were required to apply the vendor fix, or stop using the product, by 2026-03-13. Apply the vendor fix referenced above to every affected product listed in this record, then confirm the running version against the vendor advisory.
Threat activity tracking CVE-2025-49113
4 tracked threats in the Threadlinqs corpus reference CVE-2025-49113, either in the campaign’s CVE list or as an indicator on the campaign record.
- Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820 (AFD.sys) and Two Publicly Disclosed Zero-Days (CVE-2026-62832 "LegacyHive", CVE-2026-72971) — CRITICAL · 2026-08-11
- UNK_MassTraction: China-Aligned Actor Exploits Roundcube CVE-2024-42009 & CVE-2025-49113 to Deploy IceCube Stealer and VShell Against University Physics Departments — HIGH · 2026-07-13
- UNK_MassTraction Exploits Roundcube XSS/Deserialization Flaws (CVE-2024-42009, CVE-2025-49113) to Spy on Academic Researchers — HIGH · 2026-07-10
- RoundCube Webmail Active Exploitation — CVE-2025-49113 Deserialization RCE (CVSS 9.9) + CVE-2025-68461 XSS via SVG Animate Tag (CISA KEV) — CRITICAL · 2026-02-22
Sources
Seeded from nvd and not yet processed by the Threadlinqs enrichment pipeline, so blank CVSS, EPSS or KEV fields above mean NOT MEASURED rather than measured-absent.
- fearsoff.org
- github.com
- github.com (7408f31379666124a39f9cb1018f62bc5e2dc695)
- github.com (c50a07d88ca38f018a0f4a0b008e9a1deb32637e)
- github.com (9865)
- github.com (1.5)
- github.com (1.6)
- roundcube.net
- vicarius.io
- vicarius.io (cve 2025 49113 roundcube vulnerability d)
← all vulnerabilities · Markdown version · Threadlinqs Intelligence