CISA flagged two Roundcube Webmail vulnerabilities as actively exploited in attacks and ordered U.S. federal agencies to patch them within three weeks. Roundcube Webmail is a web-based email client that has been the default mail interface for the widely used cPanel web hosting control panel since 2008. The first vulnerability tagged as actively abused by threat actors is a critical remote code execution flaw tracked as CVE-2025-49113, which was first flagged as exploited days after it was patched in June 2025, when Internet security watchdog Shadowserver warned that over 84,000 vulnerable Roundcube webmail installations were vulnerable to attacks. Roundcube patched the second one (CVE-2025-68461) two months ago, in December 2025, warning that remote, unauthenticated attackers can exploit it through low-complexity cross-site scripting (XSS) attacks that abuse the animate tag in SVG documents. "We strongly recommend to update all productive installations of Roundcube 1.6.x and 1.5.x with this new versions," the Roundcube security team warned when it released versions 1.6.12 and 1.5.12 that address this security flaw. Shodan currently tracks over 46,000 Roundcube instances accessible on the internet. However, there is no information on how many of them are vulnerable to CVE-2025-49113 or CVE-2025-68461 attacks. While it didn't provide any details on attacks exploiting these two security flaws, CISA added them to its Known Exploited Vulnerabilities (KEV) Catalog on Friday, warni...
CISA: Recently patched RoundCube flaws now exploited in attacks
BleepingComputer
·Sergiu Gatlan
·Published Feb 23, 2026
·Updated
Affected Software
1 affected component
Roundcube Webmail>=1.5.12<=1.6.12
Frequently Asked Questions
1
What vulnerabilities are being discussed in the article?
The article discusses two vulnerabilities in Roundcube Webmail that have been flagged as actively exploited in attacks.
2
What actions has CISA taken regarding these vulnerabilities?
CISA has ordered U.S. federal agencies to patch the vulnerabilities within three weeks.
3
Which version of Roundcube Webmail is affected by the security flaws?
The affected versions of Roundcube Webmail are between 1.5.12 and 1.6.12.
4
What is Roundcube Webmail?
Roundcube Webmail is a web-based email client that is widely used for managing emails.
5
Why is it important to patch these vulnerabilities quickly?
It is crucial to patch these vulnerabilities quickly to prevent exploitation and potential data breaches.