Vulnerability threat dossier

CVE-2025-49113

roundcubewebmail

Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.

VTP deterministic threat58.3of 100 · CVSS excluded

VTP analyst assessment

Roundcube authenticated deserialization code execution

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence82%
Public exploitation · VTP factKEV

Assessment

CVE-2025-49113 lets an authenticated Roundcube user trigger PHP object deserialization through an unvalidated _from URL parameter. This can lead to attacker-chosen code execution. CISA KEV lists the vulnerability as known exploited globally. BleepingComputer also reports active attacks, citing the Canadian Centre for Cyber Security.

Why it matters

  • Roundcube webmail is reachable through its web interface, and a valid user account is the stated prerequisite.
  • Successful exploitation could give an attacker code execution on the Roundcube application host.
  • If you use Roundcube 1.5 before 1.5.10 or 1.6 before 1.6.11, update to a fixed release and review access to affected webmail instances.

Evidence

2 record references and 1 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.

Uncertainties

The public reporting is press reporting and does not identify affected organizations or attack details.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

Investigate unexpected authenticated requests to the Roundcube settings upload endpoint, especially those containing _from parameters.

AI baseline history (5)
  1. BASELINE ASSESSED
    Roundcube authenticated deserialization code executiongpt-5.6-terra · low
  2. BASELINE ASSESSED
    Reported active exploitation of Roundcube deserialization RCEgpt-5.6-terra · low
  3. BASELINE ASSESSED
    Roundcube Webmail PHP object deserializationgpt-5.6-terra · low
  4. BASELINE ASSESSED
    Exploited Roundcube authenticated deserialization RCEgpt-5.6-terra · low
  5. BASELINE ASSESSED
    Roundcube authenticated deserialization RCEgpt-5.6-sol · high
Technical severityCRITICALCVSS 9.9 · technical context
Public exploitationKEVGlobal public evidence
Exploit maturityTECHNICAL DETAILSReliability not implied
EPSS0.99100th percentile · prediction
Evidence confidence60%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    CISA KEV lists this vulnerability as known to be exploited globally.

  2. 02

    EPSS is 0.99; this is predictive context, not exploitation evidence.

  3. 03

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

KEV ADDEDCISA KEV entry added
03

Claim provenance

Evidence and source independence

7publications detected
7underlying evidence chains

0 primary sources · 0 dependent secondary reports · 7 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimEXPLOITATION REPORTEDPUBLICATION REPORTS EXPLOITATION
60%claim confidence
UNKNOWNreport:07493c6375dd3d347eb3aa07283b00eb4b36eb48306b9dd7adeb03938c675fb8ACTIVE
Evidence
04

Event history

Threat timeline

  1. 13:2724 Sept
    EXPLOITATION REPORTED

    Exploitation Reported

    BleepingComputer supplied a deterministically extracted signal; review the linked evidence before escalation.

  2. 13:5815 Apr
    EXPLOIT SOURCE UPDATE

    New exploit-source update

    ProjectDiscovery Nuclei Templates Releases published evidence linked to CVE-2025-49113.

  3. 00:0020 Feb
    KEV ADDED

    CISA KEV entry added

    CISA lists global known exploitation. This is not a VTP sensor observation.

05

Original publications

Source record

Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild. The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1. The issue stems from a preg_replace() backslash

CVE-2025-49113CVE-2025-68461CVE-2026-48842
Separate evidence group
Original

Roundcube Webmail Vulnerability in Attackers’ Crosshairs

Tracked as CVE-2026-48842, the exploited bug is an SQL injection that can be exploited without authentication. The post Roundcube Webmail Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek .

CVE-2024-37383CVE-2025-49113CVE-2025-68461CVE-2026-48842
Separate evidence group
Original

Hackers now exploit critical Roundcube flaw in code injection attacks

A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security. [...]

CVE-2020-12641CVE-2020-35730CVE-2021-44026CVE-2023-5631CVE-2025-49113CVE-2025-68461CVE-2026-48842
Separate evidence group
Original

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting defense and aerospace companies across France, Germany, Brazil, and India. The activity, per Check Point Research, is part of Operation Dream Job, a long-running cyber espionage and

CVE-2025-49113CVE-2026-68820
Separate evidence group
Original

Lazarus hackers exploited Windows zero-day to target defense firms

North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign. [...]

CVE-2025-49113CVE-2026-68820
Separate evidence group
Original

Fresh Windows Zero-Day Exploited in North Korean Cyberattacks

The bug allowed attackers to gain full control of the victims’ systems and deploy the ForestTiger backdoor. The post Fresh Windows Zero-Day Exploited in North Korean Cyberattacks appeared first on SecurityWeek .

CVE-2025-49113CVE-2026-68820
Separate evidence group
Original

Nuclei Templates v10.4.2 – Release Notes

New Templates Added: 121 | CVEs Added: 61 | First-time contributions: 15 🔥 Release Highlights 🔥 [ CVE-2026-21643 ] Fortinet FortiClientEMS 7.4.4 - SQL Injection ( @ritikchaddha ) [critical] 🔥 (kev) (vKEV) [ CVE-2026-35616 ] FortiClient EMS - Authentication Bypass ( @ritikchaddha ) [high] 🔥 (kev) (vKEV) [ CVE-2026-39987 ] Marimo <= 0.20.4 - Pre-Auth Terminal WebSocket RCE ( @ritikchaddha ) [critical] 🔥 (vKEV) [ CVE-2025-59528 ] Flowise - Remote Code Execution (@xtr0nix) [critical] 🔥 (vKEV) [ CVE-2026-3584 ] WordPress Kali Forms <= 2.4.9 - Remote Code Execution ( @pussycat0x ) [critical] 🔥 (vKEV) [ CVE-2026-4020 ] Gravity SMTP WordPress Plugin - Sensitive Information Exposure ( @theamanrawat ) [high] 🔥 (vKEV) [ CVE-2026-34197 ] Apache ActiveMQ - Remote Code Execution ( @dhiyaneshdk , @horizon3 ) [critical] 🔥 [ CVE-2026-34156 ] NocoBase - VM Sandbox Escape to Remote Code Execution ( @theamanrawat ) [critical] 🔥 [ CVE-2026-20079 ] Cisco Secure Firewall Management Center - Authentication Bypass ( @theamanrawat ) [critical] 🔥 [ CVE-2026-26980 ] Ghost CMS Content API - SQL Injection ( @domwhewell-sage ) [critical] 🔥 [ CVE-2026-4257 ] WordPress Contact Form by Supsystic - Server-Side Template Injection ( @theamanrawat ) [critical] 🔥 [ CVE-2026-2699 ] Progress ShareFile Storage Zones Controller - Authentication Bypass ( @dhiyaneshdk ) [critical] 🔥 [CVE-2026-33340] LoLLMs WEBUI - Server-Side Request Forgery ( @theamanrawat ) [critical] 🔥 [ CVE-2025-67303 ] ComfyUI-Manager < 3.38 - Configuration Overwrite ( @maciejklimek ) [critical] 🔥 [ CVE-2024-38819 ] Spring Framework Path Traversal in Functional Web Frameworks ( @dhiyaneshdk ) [high] 🔥 What's Changed Bug Fixes Moved CVE-2026-23829 template from incorrect http folder to the network folder (Issue #15633 , PR #15738 ). Fixed CVE-ID mismatches in template metadata (PR #15850 ). Fixed invalid CPE formats across multiple HTTP templates (PR #15751 ). Fixed tag formatting in CVE-2023-38875 , CVE-2025-11307 , CVE-2023-24322 , and CVE-2025-4210 templates (PRs #15897 , #15898 , #15899 , #15900 ). Updated CVE-2023-6825 template to correct detection logic (PR #15877 ). Corrected template author attribution from PentesterTN to 0xBassia (PR #15827 ). False Negatives Fixed false negatives in CVE-2024-8529 (LearnPress SQLi): body matchers were unreliable for blind SQLi responses and a randstr bypass was added to defeat DB query cache (Issue #15768 , PR #15844 ). False Positives Reduced extremely high false positives in credentials-disclosure template caused by over-permissive [\w-]+ value regex with no minimum length enforcement, flagging short UI strings like "ClientSecret":"Client" as credential leaks (Issue #15563 , PR #15845 ). Reduced false positives in the Apache ActiveMQ Artemis Console Default Login template; tightened matcher to require a valid JSON login response with expected artemis username (Issue #15762 , PR #15861 ). Resolved false positives in molgenis-default-login template triggered by JSESSIONID cookies on custom 404 pages (Issue #12603 ). Removed false positive subdomain takeover detection templates for Netlify, Shopify, Azure Azurewebsites, Cloudapp, and Trafficmanager - these services are no longer vulnerable due to enforced TXT verification, deprecation, or claimed namespace blocking (PR #15724 ). Fixed false positive webpack-config detection triggered by SPA catch-all routing (PR #15869 ). Improved CVE-2022-3254 matchers to reduce false positives on HTML error responses (PR #15840 ). Fixed false positives in CVE-2024-52762 (PR #15833 ). Fixed false positives in CVE-2025-49113 (PR #15777 ). Enhancements Refactored matchers in CVE-2024-42009 for improved detection accuracy (PR #15835 ). Added and normalized CWE metadata across HTTP templates (PR #15804 ). Added additional EOL version entries to end-of-life detection templates (PR #15891 ). Updated CVE-2025-30208 detection coverage (PR #15784 ). Templates Added [ CVE-2026-39987 ] Marimo <= 0.20.4 - Pre-Auth Terminal W

CVE-2021-23337CVE-2021-46371CVE-2022-3254CVE-2022-41678CVE-2023-24322CVE-2023-38875CVE-2023-40924CVE-2023-49293CVE-2023-6592CVE-2023-6750CVE-2023-6825CVE-2023-7165CVE-2024-28752CVE-2024-38819CVE-2024-42009CVE-2024-49357CVE-2024-52762CVE-2024-8252CVE-2024-8529CVE-2025-11307CVE-2025-12536CVE-2025-13652CVE-2025-14124CVE-2025-14340CVE-2025-2221CVE-2025-2558CVE-2025-30208CVE-2025-32614CVE-2025-4210CVE-2025-49113CVE-2025-50578CVE-2025-5350CVE-2025-53533CVE-2025-54597CVE-2025-55150CVE-2025-59528CVE-2025-64500CVE-2025-67303CVE-2026-20079CVE-2026-21643CVE-2026-23829CVE-2026-2416CVE-2026-25616CVE-2026-26980CVE-2026-2699CVE-2026-28358CVE-2026-28414CVE-2026-29014CVE-2026-29066CVE-2026-29183CVE-2026-30824CVE-2026-31807CVE-2026-31809CVE-2026-33340CVE-2026-33478CVE-2026-3396CVE-2026-34156CVE-2026-34197CVE-2026-34453CVE-2026-34605CVE-2026-34885CVE-2026-35616CVE-2026-3584CVE-2026-39364CVE-2026-39365CVE-2026-39987CVE-2026-4020CVE-2026-4106CVE-2026-4257CVE-2026-5615CVE-2026-6118CVE-2026-6203
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score58.3vtp-threat-v1-public
Public exploitation30 / 30
EPSS prediction19.78 / 20
Exploit availability2.5 / 15
Source independence0 / 15
Intelligence recency6 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
9.9 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE
CWE-502
CPE records
2
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.