CVE-2025-49113

Published Jun 2, 2025

Last updated 5 months ago

Exploit knownCVSS critical 9.9
Roundcube Webmail
web application
Server
Rdp
Mobile device
SMTP

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-49113 is a remote code execution vulnerability affecting Roundcube Webmail versions before 1.5.10 and 1.6.x before 1.6.11. It stems from the insufficient validation of the `_from` parameter in the `program/actions/settings/upload.php` file. This lack of validation allows for PHP Object Deserialization, potentially enabling authenticated users to execute arbitrary code on the Roundcube Webmail server. The vulnerability has been addressed in Roundcube Webmail versions 1.5.10 and 1.6.11.

Description
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.
Source
cve@mitre.org
NVD status
Analyzed
Products
webmail, debian_linux

Risk scores

CVSS 3.1

Type
Primary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Known exploits

Data from CISA

Vulnerability name
RoundCube Webmail Deserialization of Untrusted Data Vulnerability
Exploit added on
Feb 20, 2026
Exploit action due
Mar 13, 2026
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weaknesses

cve@mitre.org
CWE-502
nvd@nist.gov
CWE-502

Social media

Hype score
Not currently trending
  1. #CyberAlert | Update: Roundcube Webmail vulnerabilities CVE-2024-42009 and CVE-2025-49113 https://t.co/fjBGTsQrMa https://t.co/fyi0kpLXFO

    @cybercentre_ca

    10 Jul 2026

    486 Impressions

    1 Retweet

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. #CyberAlerte | Vulnérabilités de Roundcube Webmail CVE-2024-42009 et CVE-2025-49113 https://t.co/IZRF4UjOSw https://t.co/dk1r5jLKjx

    @centrecyber_ca

    10 Jul 2026

    93 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. a china-aligned crew (UNK_MassTraction) is quietly exploiting two roundcube webmail bugs, CVE-2024-42009 and CVE-2025-49113, to get into US and canadian university mail servers. the targeting is the tell: physics and engineering departments, the research inboxes. this is

    @PurpleOps_io

    9 Jul 2026

    132 Impressions

    1 Retweet

    2 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  4. Suspected China-aligned cluster targets US and Canadian universities via #Roundcube exploit chain: CVE-2024-42009 (CVSS 9.3) triggered by viewing a crafted email, chained with CVE-2025-49113 (CVSS 9.9) deserialization for RCE. Focus on research-value departments. https://t.co/VpI

    @MeridianEU

    9 Jul 2026

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. TRC analysis shows China-linked threat actors chained CVE-2024-42009 and CVE-2025-49113 to compromise Roundcube webmail servers at academic institutions. Attackers deployed IceCube stealer and SquareShell webshell, then moved laterally to exfiltrate research data. Runtime

    @aviatrixtrc

    9 Jul 2026

    53 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Chinese-linked UNK_MassTraction exploits CVE-2024-42009 (Roundcube XSS) to deploy IceCube stealer, then chains CVE-2025-49113 to drop SquareShell or VShell backdoor on university mail servers. Patch Roundcube now. #DFIR_Radar https://t.co/k0os84I0Dq

    @DFIR_Radar

    8 Jul 2026

    175 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  7. 中国系と疑われる脅威主体がウェブメール製品Roundcubeの脆弱性を用いて米国とカナダの教育機関を攻撃している。Proofpoint社報告。活動をUNK_MassTractionと命名。侵害契機はクロスサイトスクリプティング脆弱性

    @__kokumoto

    8 Jul 2026

    725 Impressions

    0 Retweets

    7 Likes

    4 Bookmarks

    0 Replies

    0 Quotes

  8. 🔴 Çin bağlantılı siber sadırganlar, kritik Roundcube güvenlik açıklarını kullanarak ABD ve Kanada'daki üniversiteleri hedef aldı! Zincirleme saldırıda CVE-2024-42009 ve CVE-2025-49113 istismar edilerek yalnızca e-postanın görüntülenmesiyle başlayan süreç

    @ridvanyagli

    8 Jul 2026

    979 Impressions

    2 Retweets

    7 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  9. Chinese 🇨🇳 UNK_MassTraction chained CVE-2024-42009 and CVE-2025-49113 in Roundcube to compromise university mail servers, dropping VShell backdoors and webshells. Opening a single email triggers the exploit, no user interaction beyond that. #DFIR_Radar https://t.co/gbOySIo

    @DFIR_Radar

    7 Jul 2026

    168 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  10. Suspected China-aligned group UNK_MassTraction exploited CVE-2024-42009 and CVE-2025-49113 in Roundcube to breach physics and engineering departments at fewer than 10 U.S. and Canadian universities, Proofpoint reported. https://t.co/SszBIfmduc

    @threatcluster

    7 Jul 2026

    64 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  11. TRC analysis shows UNK_MassTraction exploiting chained Roundcube vulnerabilities to compromise university mail servers. Attackers deployed webshells via CVE-2024-42009 and CVE-2025-49113, then moved laterally to exfiltrate physics and engineering research data. Runtime

    @aviatrixtrc

    7 Jul 2026

    49 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. 🚨 A suspected China-aligned threat cluster, tracked by Proofpoint as UNK_MassTraction, is exploiting Roundcube webmail flaws (CVE-2024-42009 and CVE-2025-49113) against physics and engineering departments at U.S. and Canadian universities; merely opening a malicious email

    @techepages

    7 Jul 2026

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. 🚨 Suspected China-aligned UNK_MassTraction exploited now-patched Roundcube flaws against U.S. and Canadian university departments. IceCube stole credentials, 2FA data, and cookies, then used CVE-2025-49113 to drop VShell or a web shell. How the mail server compromise worked:

    @TheHackersNews

    7 Jul 2026

    18891 Impressions

    19 Retweets

    66 Likes

    10 Bookmarks

    1 Reply

    0 Quotes

  14. Critical RCE in Roundcube 🤯🔥 Your inbox could be the attack vector. CVE-2025-49113 allows Remote Code Execution on vulnerable Roundcube instances, putting countless email servers at risk. 🚨 👨‍💻 AirCorridor / Hackers-Arise 🔗 https://t.co/R8St5Ly3ml #CyberSe

    @luckyhacker43

    14 Jun 2026

    2151 Impressions

    16 Retweets

    64 Likes

    32 Bookmarks

    4 Replies

    0 Quotes

  15. Top 5 Trending CVEs: 1 - CVE-2018-17144 2 - CVE-2026-46243 3 - CVE-2026-49975 4 - CVE-2025-49113 5 - CVE-2026-28318 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    7 Jun 2026

    95 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. Top 5 Trending CVEs: 1 - CVE-2025-49113 2 - CVE-2026-26980 3 - CVE-2026-31635 4 - CVE-2026-34908 5 - CVE-2026-42897 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    25 May 2026

    154 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. CVE-2025-49113 is a critical authenticated remote-code-execution flaw in Roundcube webmail — the default in cPanel, Plesk, and many hosting stacks — caused by insufficient validation of the _from upload parameter that lets attackers inject malicious PHP-serialized objects int

    @bytecodevm

    23 May 2026

    311 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. Your email server might be vulnerable! CVE-2025-49113 allows attackers to compromise servers without authentication. https://t.co/t6mRtvwXrh @three_cube @DI0256 @IamSmouk @co11ateral https://t.co/a9gyDen9o4

    @_aircorridor

    22 May 2026

    14360 Impressions

    33 Retweets

    191 Likes

    122 Bookmarks

    2 Replies

    0 Quotes

  19. I just completed Roundcube: CVE-2025-49113 room on TryHackMe! Exploit CVE-2025-49113 in a lab environment. https://t.co/hEntzj5esa #tryhackme via @tryhackme #tryhackme #learning #consistency

    @LittleSun4lower

    7 May 2026

    258 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. 🛡️ We added RoundCube Webmail vulnerabilities CVE-2025-49113 & CVE-2025-68461 to our Known Exploited Vulnerabilities Catalog.

    @NexusForgeCyber

    16 Mar 2026

    14 Impressions

    3 Retweets

    5 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. 🛡️ Alerta de Seguridad: Vulnerabilidad de Deserialización de Datos No Confiables en RoundCube Webmail (CVE-2025-49113) RoundCube Webmail presenta una vulnerabilidad crítica de deserialización de datos no confiables (CWE-502) que permite ejecución remota de código (RCE)

    @CiberPlanetaOrg

    16 Mar 2026

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. CVE-2025-49113 | 42 mentions | Vendors: debian, roundcube | Active Exploitation | debian_linux, webmail | 11[.]0 VulnSocial - your risk exposure provider. https://t.co/S4rp6ysUQi https://t.co/8FZCTFa4R0

    @vulnsocial

    9 Mar 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. Top 30 CVEs for ecosystem (30 days). Top CVEs: CVE-2025-40538, CVE-2025-49113, CVE-2022-20775 VulnSocial — your risk exposure provider. #vulnsocial #CVE #CyberSecurity #VulnerabilityManagement https://t.co/S02Q7THYkX

    @vulnsocial

    7 Mar 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. CVE-2025-49113 | 42 mentions | Vendors: debian, roundcube | Active Exploitation | debian_linux, webmail | 11[.]0 VulnSocial - your risk exposure provider. https://t.co/S4rp6ysUQi

    @vulnsocial

    7 Mar 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. I just completed Roundcube: CVE-2025-49113 room on TryHackMe! Exploit CVE-2025-49113 in a lab environment. https://t.co/nETHBhX5I5 #tryhackme via @tryhackme

    @ToTo13ru_xakep

    4 Mar 2026

    67 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. Top 30 CVEs for debian (30 days). Top CVEs: CVE-2011-2523, CVE-2016-5195, CVE-2025-49113 Vendors: debian VulnSocial — your risk exposure provider. #vulnsocial #Debian #CVE #CyberSecurity #VulnerabilityManagement https://t.co/iUn30r73W2

    @vulnsocial

    3 Mar 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  27. CISA KEV 警告 26/02/20: Roundcube の脆弱性 CVE-2025-49113/68461 を登録 https://t.co/FQxWlp7ZYk オープンソースの Web メール・クライアントとして普及している Roundcube Webmail において、実環境での悪用が確認された 2 件の深

    @iototsecnews

    2 Mar 2026

    124 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  28. [CRITICAL] CVE-2025-49113 and CVE-2025-68461 Added to CISA KEV Catalog CISA adds CVE-2025-49113 and CVE-2025-68461 to KEV Catalog; federal agencies must remediate by March 13, 2026. CVE: CVE-2025-49113, CVE… https://t.co/y4REX3zTlu

    @MysocAi

    26 Feb 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  29. [CRITICAL] CISA Adds Critical Roundcube Vulnerabilities to KEV Catalog CISA added CVE-2025-49113 and CVE-2025-68461 to KEV Catalog due to active exploitation. CVE: CVE-2025-49113, CVE-2025-68461 • APT: N/A … https://t.co/y4REX3zTlu

    @MysocAi

    26 Feb 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  30. [HIGH] CISA Adds CVE-2025-49113 and CVE-2025-68461 to KEV Catalog CISA added two Roundcube Webmail vulnerabilities to KEV Catalog due to active exploitation. CVE: CVE-2025-49113, CVE-2025-68461 • APT: Unkno… https://t.co/y4REX3zTlu

    @MysocAi

    26 Feb 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  31. [CRITICAL] CVE-2025-49113: Critical RCE Vulnerability in Roundcube Critical RCE vulnerability in Roundcube; patch released. CVE: CVE-2025-49113 • APT: N/A • Status: EXPLOITED Immediate patching required to… https://t.co/y4REX3zTlu

    @MysocAi

    26 Feb 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  32. [CRITICAL] CISA Adds CVE-2025-49113 to KEV Catalog CISA adds CVE-2025-49113 to KEV Catalog; agencies must remediate by March 13. CVE: CVE-2025-49113 • APT: N/A • Status: ACTIVE Federal agencies must act by… https://t.co/y4REX3zTlu

    @MysocAi

    26 Feb 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  33. [HIGH] RoundCube Webmail Vulnerabilities Added to CISA's KEV List CISA adds two RoundCube Webmail flaws to KEV list; exploitation by APT28 and Winter Vivern observed. CVE: CVE-2025-49113, CVE-2025-68… https://t.co/YUrXNPqYU3

    @MysocAi

    25 Feb 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  34. [HIGH] CISA Adds RoundCube Webmail Vulnerabilities to KEV List CVE-2025-49113 and CVE-2025-68461 in RoundCube Webmail pose significant risks. CVE: CVE-2025-49113, CVE-2025-68461 • APT: APT28 • Status… https://t.co/YUrXNPqYU3

    @MysocAi

    25 Feb 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  35. [HIGH] RoundCube Webmail Vulnerabilities Added to KEV List CISA adds two RoundCube flaws to its Known Exploited Vulnerabilities list. CVE: CVE-2025-49113, CVE-2025-68461 • APT: APT28 • Status: ACTIVE… https://t.co/YUrXNPqr4v

    @MysocAi

    25 Feb 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  36. [HIGH] CISA Warns of Active Exploitation of RoundCube Webmail Flaws CISA alerts on active exploitation of CVE-2025-49113 and CVE-2025-68461 in RoundCube Web… https://t.co/tUOR2W8DOw

    @MysocAi

    25 Feb 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  37. [CRITICAL] CISA Flags Actively Exploited Roundcube Webmail Vulnerabilities CISA added CVE-2025-49113 and CVE-2025-68461 to its KEV catalogue amid active exploitation. CVE: CVE-2025-49113, CVE-2025-68461 • APT: Unk… https://t.co/KbRLi8GoQo

    @MysocAi

    25 Feb 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  38. [HIGH] CISA Adds Roundcube Vulnerabilities to KEV Catalog CISA added CVE-2025-49113 and CVE-2025-68461 to KEV due to active exploitation. CVE: CVE-2025-49113, CVE-2025-68461 • Status: ACTIVE Indicates widespread … https://t.co/KbRLi8GoQo

    @MysocAi

    25 Feb 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  39. [CRITICAL] CISA Flags Actively Exploited Roundcube Vulnerabilities CISA added CVE-2025-49113 and CVE-2025-68461 to KEV list due to active exploitation. CVE: CVE-2025-49113, CVE-2025-68461 • APT: APT34 • Status: ACTIVE Aff… https://t.co/kYM2rfE8Mb

    @MysocAi

    25 Feb 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  40. [CRITICAL] CISA Adds Actively Exploited Roundcube Webmail Vulnerabilities to KEV Catalog CISA warns of active exploitation of CVE-2025-49113 and CVE-2025-68461 in Roundcube Webmail. CVE: CVE-2025-49113, CVE-2025-6… https://t.co/KbRLi8GoQo

    @MysocAi

    25 Feb 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  41. [CRITICAL] CISA Adds Roundcube Webmail Flaws to KEV Catalog CVE-2025-49113 and CVE-2025-68461 added due to active exploitation. CVE: CVE-2025-49113, CVE-2025-68461 • APT: N/A • Status: ACTIVE Critical vulnerabili… https://t.co/KbRLi8GoQo

    @MysocAi

    25 Feb 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  42. [HIGH] CISA Adds Roundcube Webmail Vulnerabilities to KEV Catalog CVE-2025-49113 and CVE-2025-68461 added due to active exploitation. CVE: CVE-2025-49113, CVE-2025-68461 • APT: Unknown • Status: ACTIVE Critical v… https://t.co/KbRLi8GoQo

    @MysocAi

    25 Feb 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  43. CISA alerts on active exploits of patched Roundcube Webmail flaws CVE-2025-49113 & CVE-2025-68461 tied to Winter Vivern and APT28. New AI-assisted Arkanix Stealer targets browsers, wallets, and games. #WinterVivern #ArkanixStealer #USA https://t.co/MoviDe2Gfl

    @TweetThreatNews

    25 Feb 2026

    163 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  44. [HIGH] CVE-2025-49113 and CVE-2025-68461 Exploited in RoundCube CISA warns of active exploitation of two critical vulnerabilities in RoundCube Webmail. CVE… https://t.co/tUOR2W8DOw

    @MysocAi

    24 Feb 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  45. [HIGH] CVE-2025-49113 and CVE-2025-68461 in RoundCube Webmail Actively Exploited CISA warns of active exploitation of critical vulnerabilities in RoundCube … https://t.co/tUOR2W8DOw

    @MysocAi

    24 Feb 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  46. CVE-2025-49113 / CVE-2025-68461  ⚠️ Roundcube Webmail – Actively Exploited RCE & XSS (CISA KEV)  CISA has added CVE-2025-49113 and CVE-2025-68461 to its KEV catalogue following confirmation of active in-the-wild exploitation targeting Roundcube Webmail.  CVE-2025-49

    @modat_magnify

    24 Feb 2026

    115 Impressions

    0 Retweets

    2 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  47. [HIGH] CISA Warns of Actively Exploited Roundcube Vulnerabilities CISA issues warning on CVE-2025-49113 and CVE-2025-68461 in Roundcube Webmail, urging prom… https://t.co/tUOR2W8DOw

    @MysocAi

    24 Feb 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  48. [HIGH] CISA Updates KEV Catalog with RoundCube Webmail Vulnerabilities CISA adds CVE-2025-49113 and CVE-2025-68461 to KEV catalog amid active exploitation. … https://t.co/tUOR2W8DOw

    @MysocAi

    24 Feb 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  49. 🔶 [HIGH] CISA Warns of RoundCube Webmail Exploits CISA alerts on activ… 🔴 CVE: CVE-2025-49113, CVE-2025-68461 🕵️ APT: Unspecified ⚡ Status: ACTIVE 🎯 MITRE: Initial Access, Execution ⚔️ Affects webmail services, risking unauthorized access. 🔗 https://t.co

    @MysocAi

    24 Feb 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  50. 🔶 [HIGH] CISA Warns of Active Exploitation of Roundcube Webmail Vulnerabilities CISA adds two Roundc… 🔴 CVE: CVE-2025-49113, CVE-2025-68461 🕵️ APT: Unknown ⚡ Status: ACTIVE 🎯 MITRE: Initial Access, Execution ⚔️ Requires immediate remediation to prevent expl

    @MysocAi

    24 Feb 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations