Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5022 articles · 188920 vulns · 37/41 feeds (7d)
← Back to list
9.9
CVE-2025-49113KEVEXPLOITEDPATCHED
roundcube · webmail

Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php

Description

Post-Auth RCE via PHP Object Deserialization vulnerability (CVE-2025-49113)

Affected Products

VendorProductVersions
roundcubewebmail< 1.5.10, < 1.6.11, < 1.6.17, < 1.7.2

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
canonicalubuntu linuxcert_advisory90%
cpanelcpanel/whmcert_advisory90%
debiandebian linuxcert_advisory90%
debiandebian_linuxcve_cpe95%
fedorafedora linuxcert_advisory90%

References

  • https://fearsoff.org/research/roundcube(Third Party Advisory)
  • https://github.com/roundcube/roundcubemail/commit/0376f69e958a8fef7f6f09e352c541b4e7729c4d(Patch)
  • https://github.com/roundcube/roundcubemail/commit/7408f31379666124a39f9cb1018f62bc5e2dc695(Patch)
  • https://github.com/roundcube/roundcubemail/commit/c50a07d88ca38f018a0f4a0b008e9a1deb32637e(Patch)
  • https://github.com/roundcube/roundcubemail/pull/9865(Issue Tracking)
  • https://github.com/roundcube/roundcubemail/releases/tag/1.5.10(Release Notes)
  • https://github.com/roundcube/roundcubemail/releases/tag/1.6.11(Release Notes)
  • https://roundcube.net/news/2025/06/01/security-updates-1.6.11-and-1.5.10(Vendor Advisory)
  • https://www.vicarius.io/vsociety/posts/cve-2025-49113-roundcube-mitigation-script(Exploit, Mitigation, Third Party Advisory)
  • https://www.vicarius.io/vsociety/posts/cve-2025-49113-roundcube-vulnerability-detection(Exploit, Mitigation, Third Party Advisory)
  • http://www.openwall.com/lists/oss-security/2025/06/02/3(Mailing List, Third Party Advisory)
  • https://lists.debian.org/debian-lts-announce/2025/06/msg00008.html(Mailing List, Third Party Advisory)
  • https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-49113(US Government Resource)
  • https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-49113.yaml(exploit, nuclei)

Related News (5 articles)

Tier D
Infosecurity Magazine4h ago
Lazarus Used Post-Quantum Key Exchange to Deliver Zero-Day
→ No new info (linked only)
Tier D
SecurityWeek8h ago
Fresh Windows Zero-Day Exploited in North Korean Cyberattacks
→ No new info (linked only)
Tier B
CCCS Canada32d ago
AL25-007 - Vulnerability impacting Roundcube Webmail – CVE-2025-49113 – Update 1
→ No new info (linked only)
Tier D
BleepingComputer34d ago
Hackers exploit Roundcube flaw to spy on academic researchers
→ No new info (linked only)
Tier B
BSI Advisories82d ago
[UPDATE] [hoch] Roundcube: Schwachstelle ermöglicht Codeausführung
→ No new info (linked only)
CVSS 3.19.9 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
1.6.171.7.2
CWECWE-502, CWE-502
PublishedJun 2, 2025
Last enriched32d agov3
Tags
espionagemalwarebackdoor
Trending Score120🔥
Source articles5
Independent5
Info Completeness11/14
Missing: epss, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-54432
CVE-2026-54432: Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS). The issue occurs becaus
Trending: 4
HIGHCVE-2026-54433
CVE-2026-54433: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plai
Trending: 3
CRITICALCVE-2026-62644EXP
CVE-2026-62644: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to u
Trending: 1
HIGHCVE-2026-62642EXP
CVE-2026-62642: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which ma
Trending: 1
HIGHCVE-2026-62641
CVE-2026-62641: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a craft
Trending: 1

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Vulnerability Timeline

CVE Published
Jun 2, 2025
Added to CISA KEV
Jun 2, 2025
Actively Exploited
Feb 23, 2026
Exploit Available
Feb 23, 2026
Patch Available
Feb 23, 2026
Discovered by ZDM
Apr 1, 2026
Updated: tags
Jul 8, 2026
Updated: description, affectedVersions, patchAvailable
Jul 10, 2026

Version History

v3
Last enriched 32d ago
v3Tier B32d ago

Updated description to specify Post-Auth RCE and added new affected versions and patch information.

descriptionaffectedVersionspatchAvailable
via CCCS Canada
v2Tier D34d ago

Added new tags related to espionage and malware activities associated with the vulnerability.

tags
via BleepingComputer
v1132d ago

Initial creation