logo

CISA Adds Two Actively Exploited Roundcube Flaws to KEV Catalog

ID: 4f12de42-e731-500f-b61b-10e21cf3759a

STIX ID: report--4f12de42-e731-500f-b61b-10e21cf3759a

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2026-02-21

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

CISA added two Roundcube webmail flaws (CVE-2025-49113 — deserialization RCE, CVSS 9.9; and CVE-2025-68461 — SVG XSS, CVSS 7.2) to its Known Exploited Vulnerabilities catalog after evidence of active exploitation; researchers reported rapid weaponization and an exploit for sale, and federal agencies were ordered to remediate by March 13, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.