peter bassill · operator
$ cve CVE-2025-49113 JSON

CVE-2025-49113 KEV EXPLOIT

9.9
CRITICAL · CVSS 3.1 · EPSS 98.9% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2026-03-13.

Description

Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.

Scoring

CVSS9.9 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS98.9% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-502
On CISA KEVyes — remediate by 2026-03-13
Public exploityes
Published2025-06-02
Last modified2026-06-17

CISA KEV

NameRoundCube Webmail Deserialization of Untrusted Data Vulnerability
Added2026-02-20
Due2026-03-13
Vendor / productRoundcube / Webmail
Ransomware usenone reported

Affected (2)

VendorProduct
debiandebian linux
roundcubewebmail

Public exploits

SourceTitleDate
exploit-dbRoundcube 1.6.10 - Remote Code Execution (RCE)2025-06-13

References

→ the Explorer  ·  watch your stack  ·  NVD