Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.
https://lists.debian.org/debian-lts-announce/2025/06/msg00008.html
https://www.securityweek.com/fresh-windows-zero-day-exploited-in-north-korean-cyberattacks/
https://www.infosecurity-magazine.com/news/lazarus-post-quantum-key-dream-job/
https://www.helpnetsecurity.com/2026/08/12/north-korea-lazarus-fake-job-offers/
https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html
https://thehackernews.com/2026/07/fake-notepad-plugin-delivers.html
https://www.proofpoint.com/us/blog/threat-insight/ta458-roundpress-exploits
https://hackread.com/unk-masstraction-roundcube-us-canada-universities/
https://www.infosecurity-magazine.com/news/china-aligned-cluster-roundcube/
https://www.databreachtoday.com/chinese-cyberespionage-exploits-university-roundcube-servers-a-32165
https://thehackernews.com/2026/07/suspected-china-aligned-hackers-exploit.html
https://cyberscoop.com/china-espionage-attacks-us-canada-universities-proofpoint/
https://www.securityweek.com/recent-roundcube-webmail-vulnerability-exploited-in-attacks/
https://thehackernews.com/2026/02/cisa-adds-two-actively-exploited.html
https://www.securityweek.com/exploited-vulnerability-impacts-over-80000-roundcube-servers/
https://thehackernews.com/2025/10/from-phishing-to-malware-ai-becomes.html
https://securelist.com/vulnerabilities-and-exploits-in-q2-2025/117333/
https://thehackernews.com/2025/06/critical-10-year-old-roundcube-webmail.html
https://github.com/shunfeng8421/exploit-library
https://github.com/diedromeo/CVE-Labs-2025-2026
https://github.com/shunfeng8421/security-audit
https://github.com/smadonkuan/CVE-LAb
https://github.com/ZeroTrustWraith/Exploit-PoC
https://github.com/mooder1/CVE-2025-49113
https://github.com/Lucas-Cyber-Security/CVE_Projects
https://github.com/ankitpandey383/roundcube-cve-2025-49113-lab
https://github.com/bj715/TDCVES
https://github.com/V0idA2tronaut/CVEs
https://github.com/ynvk404/cve-research
https://github.com/l4f2s4/CVE-2025-49113_exploit_cookies
https://github.com/Zuack55/Roundcube-1.6.10-Post-Auth-RCE-CVE-2025-49113-
https://github.com/Leonideath/nuclei-cve-crit-high
https://github.com/LeakForge/CVE-2025-49113
https://github.com/AC8999/CVE-2025-49113
https://github.com/SteamPunk424/CVE-2025-49113-Roundcube-RCE-PHP
https://github.com/CyberQuestor-infosec/CVE-2025-49113-Roundcube_1.6.10
https://github.com/a-s-m-asadujjaman/exploitables
https://github.com/Joelp03/CVE-2025-49113
https://github.com/hackmelocal/CVE-2025-49113-Simulation
https://github.com/issamjr/CVE-2025-49113-Scanner
https://github.com/SyFi/CVE-2025-49113
https://github.com/Ademking/CVE-2025-49113-nuclei-template
https://github.com/rxerium/CVE-2025-49113
https://www.vicarius.io/vsociety/posts/cve-2025-49113-roundcube-vulnerability-detection
https://www.vicarius.io/vsociety/posts/cve-2025-49113-roundcube-mitigation-script
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-49113
https://roundcube.net/news/2025/06/01/security-updates-1.6.11-and-1.5.10
https://github.com/roundcube/roundcubemail/releases/tag/1.6.11
https://github.com/roundcube/roundcubemail/releases/tag/1.5.10
https://github.com/roundcube/roundcubemail/pull/9865
https://github.com/roundcube/roundcubemail/commit/c50a07d88ca38f018a0f4a0b008e9a1deb32637e
https://github.com/roundcube/roundcubemail/commit/7408f31379666124a39f9cb1018f62bc5e2dc695
https://github.com/roundcube/roundcubemail/commit/0376f69e958a8fef7f6f09e352c541b4e7729c4d
Published: 2025-06-02
Updated: 2026-02-23
Known Exploited Vulnerability (KEV)
Base Score: 9
Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C
Severity: High
Base Score: 8.8
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity: High
EPSS: 0.98897
Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.
Vulnerability of Interest