Roundcube released security updates 1.6.11 and 1.5.10 to fix CVE-2025-49113, a critical post-authentication remote code execution flaw in its open-source webmail platform. The vulnerability affects versions earlier than 1.6.11 and the LTS branch earlier than 1.5.10, and stems from improper sanitization of the _from parameter in /program/actions/settings/upload.php, which can lead to PHP object deserialization and arbitrary code execution.
Researchers and national defenders reported that the flaw is being actively exploited and that public analysis of the June hotfix helped attackers develop working exploits. FearsOff published technical research and proof-of-concept details, while CSIRT.SK said exploit code is being sold on hacker forums and warned that attackers may obtain the required authenticated access through phishing, brute-force, or CSRF. Administrators were urged to upgrade immediately and review Roundcube, network, and security logs for signs of compromise.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
CSIRT.SK reported that CVE-2025-49113 in Roundcube was being actively exploited and that a working exploit derived from analysis of the June 1 hotfix was being sold on hacker forums. The advisory urged administrators to upgrade immediately and review logs for signs of exploitation.
FearsOff published technical research on Roundcube CVE-2025-49113, describing post-authentication remote code execution via PHP object deserialization. CSIRT.SK states that FearsOff also published proof-of-concept exploit code demonstrating the issue.
Roundcube released versions 1.6.11 and 1.5.10 to address CVE-2025-49113, a critical post-authentication remote code execution flaw affecting earlier versions. The hotfix later enabled researchers and attackers to analyze the vulnerability in detail.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
csirt.sk
Open sourcefearsoff.org
Open sourceroundcube.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.