CVE-2025-49113: listed in the CISA KEV catalog CVE-2025-49113 · CVSS 9.9 CRITICAL · EPSS 98% · KEV 2026-02-20
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.
Is CVE-2025-49113 exploited? Listed in the CISA KEV catalog on 2026-02-20. Federal remediation due 2026-03-13. Past that date by 155 days. EPSS puts exploitation in the next 30 days at 98%. Public exploit code: packaged in a public tool. Public detection rules exist. Which products and versions are affected? No affected package list recorded here yet.
Is there a patch? No patch identifier recorded here yet.
What PlainSec published about CVE-2025-49113 Primary sources What this record does not say No affected package data. No patch identifier. KEV and EPSS are re-checked daily. Record last updated 2026-08-11.
CVE-2025-49113: listed in the CISA KEV catalog CVE-2025-49113 · CVSS 9.9 CRITICAL · EPSS 98% · KEV 2026-02-20
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.
Is CVE-2025-49113 exploited? Listed in the CISA KEV catalog on 2026-02-20. Federal remediation due 2026-03-13. Past that date by 155 days. EPSS puts exploitation in the next 30 days at 98%. Public exploit code: packaged in a public tool. Public detection rules exist. Which products and versions are affected? No affected package list recorded here yet.
Is there a patch? No patch identifier recorded here yet.
What PlainSec published about CVE-2025-49113 Primary sources What this record does not say No affected package data. No patch identifier. KEV and EPSS are re-checked daily. Record last updated 2026-08-11.