How to find Roundcube Webmail on your network
ID: 6abe7f04-2140-54c6-a3b5-93d6c082b7ee
STIX ID: report--6abe7f04-2140-54c6-a3b5-93d6c082b7ee
Feed Name: runZero Blog
Roundcube Webmail versions 1.5 prior to 1.5.10 and 1.6 prior to 1.6.11 are affected by CVE-2025-49113, a critical (CVSS 9.9) authenticated remote code execution vulnerability caused by PHP object deserialization of an unvalidated _from parameter in program/actions/settings/upload.php. The vulnerability has existed for ~10 years and there is evidence of active exploitation in the wild; Roundcube has released updates (1.5.10 and 1.6.11+) and the advisory includes detection guidance and a runZero query to locate potentially impacted assets—administrators should apply patches immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
