logo

PoC Code Escalates Roundcube Vuln Threat

ID: 92d987ba-5b7f-5aec-94a0-7184b8755383

STIX ID: report--92d987ba-5b7f-5aec-94a0-7184b8755383

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2025-06-10

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

A critical RCE vulnerability (CVE-2025-49113) in Roundcube webmail (affecting versions 1.1.0–1.6.10) has been disclosed and quickly weaponized with public proof-of-concept code; maintainers released patches (1.6.11 and 1.5.10) on June 1. ShadowServer reports roughly 85,000 likely unpatched instances worldwide, and threat actors — including the Belarus-linked UNC1151 conducting credential-theft campaigns — increase the risk that attackers will combine account compromise with this RCE to fully take over servers, so organizations should patch immediately and monitor file uploads and session activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.