Executive Summary
In February 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two critical vulnerabilities affecting Roundcube webmail software to its Known Exploited Vulnerabilities (KEV) catalog, citing active exploitation. The first, CVE-2025-49113, is a deserialization flaw allowing remote code execution by authenticated users due to improper validation of the '_from' parameter in 'upload.php'. The second, CVE-2025-68461, is a cross-site scripting vulnerability via the 'animate' tag in SVG documents. Both vulnerabilities have been exploited by threat actors, including nation-state groups like APT28 and Winter Vivern, to steal login credentials and spy on sensitive communications. (thehackernews.com)
The inclusion of these vulnerabilities in the KEV catalog underscores the persistent targeting of webmail platforms by sophisticated adversaries. Organizations using Roundcube are urged to apply the latest security patches promptly to mitigate potential risks. (thehackernews.com)
Why This Matters Now
The active exploitation of these vulnerabilities highlights the ongoing threat to webmail platforms, emphasizing the need for immediate patching and enhanced security measures to protect sensitive communications.
Attack Path Analysis
An attacker exploited a deserialization vulnerability in Roundcube Webmail to gain initial access, escalated privileges by executing arbitrary code, moved laterally within the network, established command and control channels, exfiltrated sensitive data, and caused significant operational disruption.
Kill Chain Progression
Initial Compromise
Description
The attacker exploited CVE-2025-49113, a deserialization vulnerability in Roundcube Webmail, to execute arbitrary code on the server.
Related CVEs
CVE-2025-49113
CVSS 8.8A deserialization of untrusted data vulnerability in Roundcube allows authenticated users to execute arbitrary code via the _from parameter in a URL.
Affected Products:
Roundcube Webmail – < 1.6.12
Exploit Status:
exploited in the wildCVE-2025-68461
CVSS 6.1A cross-site scripting vulnerability in Roundcube via the animate tag in an SVG document allows attackers to execute arbitrary JavaScript.
Affected Products:
Roundcube Webmail – < 1.6.12
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Command and Scripting Interpreter: Windows Command Shell
Exploitation for Client Execution
Process Injection
Application Layer Protocol: Web Protocols
Phishing: Spearphishing Attachment
User Execution: Malicious File
Exploitation for Defense Evasion
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Application and Workload Security
Control ID: Pillar 3
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Federal agencies face active Roundcube exploitation with March 2026 CISA remediation deadline, requiring immediate patching of CVE-2025-49113 and CVE-2025-68461 vulnerabilities.
Information Technology/IT
IT service providers managing Roundcube webmail infrastructure exposed to remote code execution attacks, requiring urgent security updates and client notification procedures.
Financial Services
Banking and financial institutions using Roundcube for email communications vulnerable to data exfiltration through deserialization attacks and cross-site scripting exploits.
Health Care / Life Sciences
Healthcare organizations face HIPAA compliance violations and patient data exposure through actively exploited Roundcube vulnerabilities affecting encrypted communications and segmentation controls.
Sources
- CISA Adds Two Actively Exploited Roundcube Flaws to KEV Cataloghttps://thehackernews.com/2026/02/cisa-adds-two-actively-exploited.htmlVerified
- CISA Adds Two Known Exploited Vulnerabilities to Cataloghttps://www.cisa.gov/news-events/alerts/2026/02/20/cisa-adds-two-known-exploited-vulnerabilities-catalogVerified
- Critical 10-Year-Old Roundcube Webmail Vulnerability Patchedhttps://thehackernews.com/2025/06/critical-10-year-old-roundcube-webmail.htmlVerified
- Security Updates 1.6.12 and 1.5.12https://roundcube.net/news/2025/12/13/security-updates-1.6.12-and-1.5.12Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have constrained the attacker's lateral movement and data exfiltration, thereby reducing the overall impact.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix CNSF may not prevent the initial exploitation, it could limit the attacker's ability to move laterally and access other systems.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation could limit the attacker's ability to leverage elevated privileges to access other systems.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security could restrict unauthorized lateral movement, thereby limiting the attacker's ability to compromise additional systems.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control could detect and potentially disrupt unauthorized command and control communications.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement could limit unauthorized data exfiltration by controlling outbound traffic.
While Aviatrix CNSF may not prevent the initial compromise, it could limit the attacker's ability to propagate ransomware and delete data across multiple systems.
Impact at a Glance
Affected Business Functions
- Email Communication
- User Authentication
Estimated downtime: 3 days
Estimated loss: $50,000
Potential exposure of sensitive email communications and user credentials.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement within the network.
- • Deploy Inline IPS (Suricata) to detect and prevent exploitation attempts.
- • Enforce Egress Security & Policy Enforcement to control outbound traffic and prevent data exfiltration.
- • Utilize Threat Detection & Anomaly Response to identify and respond to suspicious activities.
- • Ensure all systems are updated to the latest versions to mitigate known vulnerabilities.



