Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
CISA Highlights Exploited Roundcube Vulnerabilities

CISA Highlights Exploited Roundcube Vulnerabilities

Posted on February 21, 2026 By CWS

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently updated its Known Exploited Vulnerabilities (KEV) catalog with two critical security issues affecting the Roundcube webmail platform. These vulnerabilities, which have been actively exploited, necessitate immediate attention from cybersecurity professionals.

Details of the Identified Flaws

The first vulnerability, identified as CVE-2025-49113, holds a CVSS score of 9.9. This serious issue involves the deserialization of untrusted data, enabling remote code execution by authenticated users due to the lack of validation on the _from parameter within a specific URL. This flaw was addressed in a security patch released in June 2025.

Another flaw, CVE-2025-68461, presents a cross-site scripting vulnerability through the animate tag in SVG documents. Although it has a lower CVSS score of 7.2, it remains a significant concern, having been rectified in a December 2025 update.

Discovery and Exploitation

FearsOff, a cybersecurity firm based in Dubai, was instrumental in uncovering CVE-2025-49113. The company’s founder, Kirill Firsov, reported that the vulnerability was exploited within 48 hours of its public disclosure, with exploits becoming available for purchase shortly thereafter.

Firsov highlighted the ease of triggering this vulnerability on standard installations and noted its presence in the codebase for over a decade. Although the specific actors exploiting these flaws remain unidentified, previous attacks on Roundcube have involved nation-state groups such as APT28 and Winter Vivern.

Urgent Remediation Required

The Federal Civilian Executive Branch (FCEB) agencies have been mandated to address these vulnerabilities by March 13, 2026. This directive is part of a broader effort to safeguard networks from these active threats.

In light of these developments, organizations using Roundcube are urged to apply the necessary patches and review their security measures to prevent potential breaches.

As cyber threats continue to evolve, it is crucial for entities to stay informed and proactive in their security strategies to mitigate the risks associated with such vulnerabilities.

The Hacker News Tags:CISA, Cybersecurity, email software, Exploits, FCEB, nation-state actors, patch management, Roundcube, security flaws, Vulnerabilities

Post navigation

Previous Post: Anthropic Introduces AI-Driven Code Security Analysis
Next Post: EC-Council Boosts AI Workforce with New Certifications

Related Posts

SlopAds Fraud Ring Exploits 224 Android Apps to Drive 2.3 Billion Daily Ad Bids SlopAds Fraud Ring Exploits 224 Android Apps to Drive 2.3 Billion Daily Ad Bids The Hacker News
Fake Security Plugin on WordPress Enables Remote Admin Access for Attackers Fake Security Plugin on WordPress Enables Remote Admin Access for Attackers The Hacker News
RondoDox Botnet Exploits Critical React2Shell Flaw to Hijack IoT Devices and Web Servers RondoDox Botnet Exploits Critical React2Shell Flaw to Hijack IoT Devices and Web Servers The Hacker News
The Wild West of Shadow IT The Wild West of Shadow IT The Hacker News
VS Code Forks Recommend Missing Extensions, Creating Supply Chain Risk in Open VSX VS Code Forks Recommend Missing Extensions, Creating Supply Chain Risk in Open VSX The Hacker News
Golden Chickens Deploy TerraStealerV2 to Steal Browser Credentials and Crypto Wallet Data Golden Chickens Deploy TerraStealerV2 to Steal Browser Credentials and Crypto Wallet Data The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • EC-Council Boosts AI Workforce with New Certifications
  • CISA Highlights Exploited Roundcube Vulnerabilities
  • Anthropic Introduces AI-Driven Code Security Analysis
  • Anthropic Introduces Claude Code Security for AI Vulnerability Scanning
  • FBI Warns of Ploutus Malware Draining ATMs Nationwide

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • EC-Council Boosts AI Workforce with New Certifications
  • CISA Highlights Exploited Roundcube Vulnerabilities
  • Anthropic Introduces AI-Driven Code Security Analysis
  • Anthropic Introduces Claude Code Security for AI Vulnerability Scanning
  • FBI Warns of Ploutus Malware Draining ATMs Nationwide

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News