Email Security

Recent RoundCube Webmail Vulnerability Exploited in Attacks

Patched in December 2025, the exploited flaw leads to XSS attacks via the animate tags in SVG documents.

Email hack

The US cybersecurity agency CISA on Friday warned of two RoundCube Webmail vulnerabilities being exploited in the wild.

Prevalent within government and enterprise networks, RoundCube Webmail is a popular target for hackers, who have been observed exploiting flaws in the email client within days of public disclosure.

This was the case in June last year with CVE-2025-49113 (CVSS score of 9.9), a post-authentication remote code execution (RCE) issue that was added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on Friday.

The critical bug was introduced over a decade ago and impacts all RoundCube versions 1.1.0 through 1.6.10, allowing attackers to include a payload in the name of files to be uploaded, leading to data being injected in the current session.

The security defect was patched on June 1, 2025, and threat actors devised exploit code targeting it within days, claiming that credentials needed for successful exploitation could be brute forced.

On Friday, CISA warned that, in addition to CVE-2025-49113, threat actors have been exploiting CVE-2025-68461 (CVSS score of 7.2), a high-severity RoundCube vulnerability patched in December 2025.

Advertisement. Scroll to continue reading.

The flaw, an XSS issue exploitable via the animate tag in an SVG document, was resolved in Webmail versions 1.6.12 and 1.5.12.

The vulnerable RoundCube releases did not properly sanitize malicious payloads that could be embedded in the animate tag, allowing attackers to execute code in the context of the victim’s browser session without user interaction.

CISA has urged federal agencies to patch both RoundCube vulnerabilities within three weeks, as mandated by Binding Operational Directive (BOD) 22-01.

All organizations are advised to review CISA’s KEV catalog and prioritize addressing the security defects it contains.

Related: BeyondTrust Vulnerability Exploited in Ransomware Attacks

Related: Dell RecoverPoint Zero-Day Exploited by Chinese Cyberespionage Group

Related: Google Patches First Actively Exploited Chrome Zero-Day of 2026

Related: CISA Warns of Exploited SolarWinds, Notepad++, Microsoft Vulnerabilities

Related Content

Data Protection

Squidbleed, discovered with the aid of Claude Mythos Preview, has been described as a Heartbleed-style vulnerability. 

Vulnerabilities

Vulnerable WordPress plugin iterations leak API keys, secrets, tokens, server information, and other data.

Vulnerabilities

CISA has given federal agencies only three days to patch CVE-2026-20253, which can be exploited for unauthenticated remote code execution.

Vulnerabilities

Splunk patched an OS command injection in AI Toolkit, while Atlassian fixed dozens of flaws in third-party dependencies.

Network Security

Insufficient validation of user input allows an attacker to gain access to the underlying OS and elevate their privileges to root.

Vulnerabilities

Critical flaws in NGINX could allow remote, unauthenticated attackers to cause a restart and potentially execute arbitrary code.

ICS/OT

The industrial automation giant has fixed security holes in Logix, CompactLogix, Flex, RSLinx, and FactoryTalk products.

Vulnerabilities

Oracle has released its June 2026 Critical Security Patch Update to fix vulnerabilities in Communications, EBS, Enterprise Manager and other products.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version