By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: CISA Adds Two Actively Exploited Roundcube Flaws to KEV Catalog
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > CISA Adds Two Actively Exploited Roundcube Flaws to KEV Catalog
Computing

CISA Adds Two Actively Exploited Roundcube Flaws to KEV Catalog

News Room
Last updated: 2026/02/21 at 3:27 AM
News Room Published 21 February 2026
Share
CISA Adds Two Actively Exploited Roundcube Flaws to KEV Catalog
SHARE

Ravie LakshmananFeb 21, 2026Vulnerability / Patch Management

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Roundcube webmail software to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

The vulnerabilities in question are listed below –

  • CVE-2025-49113 (CVSS score: 9.9) – A deserialization of untrusted data vulnerability that allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php. (Fixed in June 2025)
  • CVE-2025-68461 (CVSS score: 7.2) – A cross-site scripting vulnerability via the animate tag in an SVG document. (Fixed in December 2025)

Dubai-based cybersecurity company FearsOff, whose founder and CEO, Kirill Firsov, was credited with discovering and reporting CVE-2025-49113, said attackers have already “diffed and weaponized the vulnerability” within 48 hours of public disclosure of the flaw. An exploit for the vulnerability was subsequently made available for sale on June 4, 2025.

Firsov also noted that the shortcoming can be triggered reliably on default installations, and that it had been hidden in the codebase for over 10 years.

There are no details on who is behind the exploitation of the two Roundcube flaws. But multiple vulnerabilities in the email software have been weaponized by nation-state threat actors like APT28 and Winter Vivern.

Federal Civilian Executive Branch (FCEB) agencies are to remediate identified vulnerabilities by March 13, 2026, to secure their networks against the active threat.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Apple's new MacBook colors nearly debuted in 2022 MacBook Air Apple's new MacBook colors nearly debuted in 2022 MacBook Air
Next Article Anker’s powerful home theater on wheels is pure chaos Anker’s powerful home theater on wheels is pure chaos
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

UK AI alignment project gets OpenAI and Microsoft boost | Computer Weekly
UK AI alignment project gets OpenAI and Microsoft boost | Computer Weekly
News
Pinterest SEO: 12 Tips to Optimize Your Pins for Search –  Blog
Pinterest SEO: 12 Tips to Optimize Your Pins for Search – Blog
Computing
.NET 11 Preview 1 Arrives With Runtime Async, Zstandard Support, and C# 15 Features
.NET 11 Preview 1 Arrives With Runtime Async, Zstandard Support, and C# 15 Features
News
Founder of Alibaba grocery chain Freshippo launches new pet retail venture · TechNode
Founder of Alibaba grocery chain Freshippo launches new pet retail venture · TechNode
Computing

You Might also Like

Pinterest SEO: 12 Tips to Optimize Your Pins for Search –  Blog
Computing

Pinterest SEO: 12 Tips to Optimize Your Pins for Search – Blog

3 Min Read
Founder of Alibaba grocery chain Freshippo launches new pet retail venture · TechNode
Computing

Founder of Alibaba grocery chain Freshippo launches new pet retail venture · TechNode

1 Min Read
Adaptive Atelier wants accessibility built in, not bolted on
Computing

Adaptive Atelier wants accessibility built in, not bolted on

8 Min Read
12 Brands on Pinterest with Awesome Marketing Strategies –  Blog
Computing

12 Brands on Pinterest with Awesome Marketing Strategies – Blog

2 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?