PatchSiren cyber security CVE debrief
CVE-2025-49113 Roundcube CVE debrief
CVE-2025-49113 is a Roundcube Webmail deserialization of untrusted data vulnerability that CISA has added to the Known Exploited Vulnerabilities (KEV) catalog, which indicates confirmed exploitation in the wild. The official guidance provided in the source corpus is to apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Vendor
- Roundcube
- Product
- Webmail
- CVSS
- CRITICAL 9.9
- CISA KEV
- Listed
- Original CVE published
- 2026-02-20
- Original CVE updated
- 2026-02-20
- Advisory published
- 2026-02-20
- Advisory updated
- 2026-02-20
Who should care
Organizations that run Roundcube Webmail, especially administrators responsible for email systems, hosted webmail services, and any environment where Roundcube is exposed to users or reachable from the internet. Security teams should also care if Roundcube is part of a managed service or shared hosting platform.
Technical summary
The vulnerability is described as a deserialization of untrusted data issue in Roundcube Webmail. The supplied corpus does not include deeper technical impact details, affected version ranges, or exploitation mechanics, but CISA’s KEV inclusion means this issue is considered actively exploited and should be prioritized for remediation based on vendor guidance.
Defensive priority
High. KEV inclusion and a CISA remediation deadline make this a near-term operational priority for exposure assessment, patching, and mitigation verification.
Recommended defensive actions
- Review the Roundcube vendor security update notices linked in the CISA metadata for remediation guidance.
- Apply vendor-recommended mitigations or updates as soon as possible.
- If Roundcube is provided as a cloud or hosted service, follow applicable BOD 22-01 guidance.
- If no effective mitigation is available, discontinue use of the product until a safe remedial path exists.
- Confirm whether any internet-facing Roundcube deployments remain exposed and document remediation status before the KEV due date.
Evidence notes
The source corpus identifies CVE-2025-49113 as a Roundcube Webmail deserialization of untrusted data vulnerability and marks it as a CISA KEV entry. CISA metadata lists the date added as 2026-02-20 and the due date as 2026-03-13. The corpus also references Roundcube security update notices (1.6.11 and 1.5.10), but no version-impact details were provided in the supplied material, so this debrief avoids unsupported version claims.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-49113 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-49113
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-49113 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-49113
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
-
CISA Known Exploited Vulnerabilities catalog
Publisher, destination, and source semantics verified
URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
cisa_kev
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.