PatchSiren cyber security CVE debrief
CVE-2025-68461 Roundcube CVE debrief
CVE-2025-68461 is a Roundcube Webmail cross-site scripting (XSS) vulnerability. CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on 2026-02-20, which makes remediation a high priority for any organization that still operates affected Roundcube deployments. The vendor notes referenced in the source corpus point to security updates 1.6.12 and 1.5.12.
- Vendor
- Roundcube
- Product
- Webmail
- CVSS
- HIGH 7.2
- CISA KEV
- Listed
- Original CVE published
- 2026-02-20
- Original CVE updated
- 2026-02-20
- Advisory published
- 2026-02-20
- Advisory updated
- 2026-02-20
Who should care
Organizations that self-host or administer Roundcube Webmail, email and collaboration platform owners, managed service providers, and security teams responsible for patching internet-facing or externally accessible webmail systems.
Technical summary
The supplied record identifies the issue as a cross-site scripting vulnerability in Roundcube Webmail. The available source metadata does not provide a CVSS score or exploit details, but it does show that CISA listed the CVE in KEV on 2026-02-20 and that the vendor’s advisory references security updates 1.6.12 and 1.5.12. Because XSS flaws can enable session theft, unauthorized actions in a user context, or phishing-style abuse inside the webmail application, exposed webmail instances should be treated as urgent patch candidates.
Defensive priority
High. KEV-listed vulnerability with a due date of 2026-03-13 in the supplied timeline; organizations should prioritize remediation immediately.
Recommended defensive actions
- Apply the vendor-referenced Roundcube security updates as soon as possible.
- Verify whether any Roundcube Webmail instances are deployed in your environment, including managed or third-party hosted services.
- If mitigation cannot be applied promptly, restrict access to the affected webmail service until remediation is complete.
- Review authentication, session, and application logs for unusual activity involving Roundcube Webmail.
- Track the CISA KEV due date (2026-03-13) and ensure remediation is completed before then.
Evidence notes
This debrief is limited to the supplied source corpus and official links. The key evidence points are: the CISA KEV record for Roundcube Webmail, the provided KEV metadata showing dateAdded 2026-02-20 and dueDate 2026-03-13, and the source notes referencing Roundcube security updates 1.6.12 and 1.5.12 plus a vendor commit and NVD detail page. No CVSS score was provided in the source data.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-68461 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-68461
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-68461 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-68461
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
-
CISA Known Exploited Vulnerabilities catalog
Publisher, destination, and source semantics verified
URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
cisa_kev
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.