Post-Auth RCE via PHP Object Deserialization vulnerability (CVE-2025-49113)
| Vendor | Product | Versions |
|---|---|---|
| roundcube | webmail | < 1.5.10, < 1.6.11, < 1.6.17, < 1.7.2 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| canonical | ubuntu linux | cert_advisory | 90% |
| cpanel | cpanel/whm | cert_advisory | 90% |
| debian | debian linux | cert_advisory | 90% |
| debian | debian_linux | cve_cpe | 95% |
| fedora | fedora linux | cert_advisory | 90% |
Updated description to specify Post-Auth RCE and added new affected versions and patch information.
Added new tags related to espionage and malware activities associated with the vulnerability.
Initial creation