Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4996 articles · 189019 vulns · 37/41 feeds (7d)
← Back to list
9.9
CVE-2025-49113KEVEXPLOITEDPATCHED
roundcube · webmail

Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php

Description

Post-Auth RCE via PHP Object Deserialization vulnerability (CVE-2025-49113)

Affected Products

VendorProductVersions
roundcubewebmail< 1.5.10, < 1.6.11, < 1.6.17, < 1.7.2

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
canonicalubuntu linuxcert_advisory90%
cpanelcpanel/whmcert_advisory90%
debiandebian linuxcert_advisory90%
debiandebian_linuxcve_cpe95%
fedorafedora linuxcert_advisory90%

References

  • https://fearsoff.org/research/roundcube(Third Party Advisory)
  • https://github.com/roundcube/roundcubemail/commit/0376f69e958a8fef7f6f09e352c541b4e7729c4d(Patch)
  • https://github.com/roundcube/roundcubemail/commit/7408f31379666124a39f9cb1018f62bc5e2dc695(Patch)
  • https://github.com/roundcube/roundcubemail/commit/c50a07d88ca38f018a0f4a0b008e9a1deb32637e(Patch)
  • https://github.com/roundcube/roundcubemail/pull/9865(Issue Tracking)
  • https://github.com/roundcube/roundcubemail/releases/tag/1.5.10(Release Notes)
  • https://github.com/roundcube/roundcubemail/releases/tag/1.6.11(Release Notes)
  • https://roundcube.net/news/2025/06/01/security-updates-1.6.11-and-1.5.10(Vendor Advisory)
  • https://www.vicarius.io/vsociety/posts/cve-2025-49113-roundcube-mitigation-script(Exploit, Mitigation, Third Party Advisory)
  • https://www.vicarius.io/vsociety/posts/cve-2025-49113-roundcube-vulnerability-detection(Exploit, Mitigation, Third Party Advisory)
  • http://www.openwall.com/lists/oss-security/2025/06/02/3(Mailing List, Third Party Advisory)
  • https://lists.debian.org/debian-lts-announce/2025/06/msg00008.html(Mailing List, Third Party Advisory)
  • https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-49113(US Government Resource)
  • https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-49113.yaml(exploit, nuclei)

Related News (6 articles)

Tier D
The Hacker News2h ago
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
→ No new info (linked only)
Tier D
Infosecurity Magazine6h ago
Lazarus Used Post-Quantum Key Exchange to Deliver Zero-Day
→ No new info (linked only)
Tier D
SecurityWeek11h ago
Fresh Windows Zero-Day Exploited in North Korean Cyberattacks
→ No new info (linked only)
Tier B
CCCS Canada33d ago
AL25-007 - Vulnerability impacting Roundcube Webmail – CVE-2025-49113 – Update 1
→ No new info (linked only)
Tier D
BleepingComputer35d ago
Hackers exploit Roundcube flaw to spy on academic researchers
→ No new info (linked only)
Tier B
BSI Advisories82d ago
[UPDATE] [hoch] Roundcube: Schwachstelle ermöglicht Codeausführung
→ No new info (linked only)
CVSS 3.19.9 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
1.6.171.7.2
CWECWE-502, CWE-502
PublishedJun 2, 2025
Last enriched33d agov3
Tags
espionagemalwarebackdoor
Trending Score125🔥
Source articles6
Independent6
Info Completeness11/14
Missing: epss, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-54432
CVE-2026-54432: Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS). The issue occurs becaus
Trending: 4
HIGHCVE-2026-54433
CVE-2026-54433: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plai
Trending: 2
CRITICALCVE-2026-62644EXP
CVE-2026-62644: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to u
Trending: 1
HIGHCVE-2026-62642EXP
CVE-2026-62642: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which ma
Trending: 1
HIGHCVE-2026-62641
CVE-2026-62641: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a craft
Trending: 1

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Vulnerability Timeline

CVE Published
Jun 2, 2025
Added to CISA KEV
Jun 2, 2025
Actively Exploited
Feb 23, 2026
Exploit Available
Feb 23, 2026
Patch Available
Feb 23, 2026
Discovered by ZDM
Apr 1, 2026
Updated: tags
Jul 8, 2026
Updated: description, affectedVersions, patchAvailable
Jul 10, 2026

Version History

v3
Last enriched 33d ago
v3Tier B33d ago

Updated description to specify Post-Auth RCE and added new affected versions and patch information.

descriptionaffectedVersionspatchAvailable
via CCCS Canada
v2Tier D35d ago

Added new tags related to espionage and malware activities associated with the vulnerability.

tags
via BleepingComputer
v1133d ago

Initial creation