CISA Adds Two Actively Exploited Roundcube Flaws to KEV Catalog
ID: 4f12de42-e731-500f-b61b-10e21cf3759a
STIX ID: report--4f12de42-e731-500f-b61b-10e21cf3759a
Feed Name: The Hacker News
Threat Score
CISA added two Roundcube webmail flaws (CVE-2025-49113 — deserialization RCE, CVSS 9.9; and CVE-2025-68461 — SVG XSS, CVSS 7.2) to its Known Exploited Vulnerabilities catalog after evidence of active exploitation; researchers reported rapid weaponization and an exploit for sale, and federal agencies were ordered to remediate by March 13, 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
