Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Exploited Vulnerability Impacts Over 80,000 Roundcube Servers

Exploited Vulnerability Impacts Over 80,000 Roundcube Servers

Posted on June 10, 2025June 10, 2025 By CWS

Greater than 80,000 Roundcube webmail servers are affected by a critical-severity distant code execution (RCE) vulnerability that has already been exploited in assaults.

Tracked as CVE-2025-49113 (CVSS rating of 9.9), the flaw is described as a post-authentication RCE by way of PHP Object Deserialization and impacts all Roundcube variations launched over the previous decade (1.1.0 by way of 1.6.10).

Based on safety researcher Kirill Firsov, who reported the safety defect, the foundation trigger is a flawed logic incorrectly evaluating variable names that start with an exclamation mark (!), which ends up in session corruption and PHP Object Injection.

The shortage of sanitization of a selected parameter permits an attacker to incorporate a payload within the title of information to be uploaded, leading to information being injected within the present session, Firsov says.

The vulnerability has remained hidden in Roundcube’s code for greater than 10 years, it may be reproduced on default installations, requires no dependencies, and its exploitation just isn’t detected by firewalls, the researcher notes.

“This vulnerability impacts Roundcube variations 1.1.0 by way of 1.6.10, together with default installs in cPanel, Plesk, ISPConfig, and others,” he says.

Firsov additionally warned that risk actors devised exploit code for the bug inside days after patches have been included in Roundcube variations 1.6.11 and 1.5.10, which have been launched on June 1.  

“The exploit for CVE-2025-49113 is already accessible on the market on the darkish net. I really feel sorry for anybody who hasn’t upgraded to the most recent model but,” the researcher warned on June 4.Commercial. Scroll to proceed studying.

Over the weekend, The Shadowserver Basis warned that roughly 84,000 unpatched Roundcube situations have been seen on the web. As of June 9, their information reveals greater than 85,000 susceptible servers.

Profitable exploitation of the safety defect requires a sound username and password, however the risk actor promoting the exploit claims that credentials might be brute-forced or extracted from logs.

Actually, CERT Poland on Friday warned that risk actors are exploiting a Roundcube XSS flaw in a spear-phishing marketing campaign geared toward credential theft. CERT Poland attributed the exercise to the Belarusian hacking group UNC1151.

Tracked as CVE-2024-42009, the flaw results in JavaScript code execution when opening an electronic mail. The US cybersecurity company CISA added the safety defect to its Recognized Exploited Vulnerabilities (KEV) catalog on Wednesday, urging federal companies to patch it by June 30.

Associated: Roundcube Webmail Vulnerability Exploited in Authorities Assault

Associated: CISA Warns of Exploited GeoServer, Linux Kernel, and Roundcube Vulnerabilities

Associated: Russian Cyberspies Exploit Roundcube Flaws In opposition to European Governments

Security Week News Tags:Exploited, Impacts, Roundcube, Servers, Vulnerability

Post navigation

Previous Post: Vulnerabilities Exposed Phone Number of Any Google User
Next Post: Researcher Found Flaw to Discover Phone Numbers Linked to Any Google Account

Related Posts

Pro-Iranian Group Hacks FBI Director’s Account Pro-Iranian Group Hacks FBI Director’s Account Security Week News
Trump Directs Federal Agencies to Cease Anthropic Technology Trump Directs Federal Agencies to Cease Anthropic Technology Security Week News
TeamFiltration Abused in Entra ID Account Takeover Campaign TeamFiltration Abused in Entra ID Account Takeover Campaign Security Week News
Record-Breaking DDoS Attack Peaks at 22 Tbps and 10 Bpps Record-Breaking DDoS Attack Peaks at 22 Tbps and 10 Bpps Security Week News
Andreas Gaetje: Journey from Economics to Körber CISO Andreas Gaetje: Journey from Economics to Körber CISO Security Week News
AI Scam Unveils 150 Fake Law Firm Websites AI Scam Unveils 150 Fake Law Firm Websites Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • WhatsApp Introduces Scam Alert to Enhance User Safety
  • Lazarus Exploits Windows Flaw to Deploy New Backdoor
  • AI-Powered Cyberattack Targets Taiwan Government
  • Ivanti EPM Update Resolves Critical Security Flaws
  • Adobe ColdFusion Flaws Pose Severe Security Risks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • WhatsApp Introduces Scam Alert to Enhance User Safety
  • Lazarus Exploits Windows Flaw to Deploy New Backdoor
  • AI-Powered Cyberattack Targets Taiwan Government
  • Ivanti EPM Update Resolves Critical Security Flaws
  • Adobe ColdFusion Flaws Pose Severe Security Risks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark