LIVE NEWS
  • OpenAI announces GPT-5.5, its latest artificial intelligence model
  • OpenAI’s new Privacy Filter runs on your laptop so PII never hits the cloud
  • Wildfires in Florida after dry winter and spring lead to drought across US | Drought
  • Election countdown in the birthplace of modern circus
  • Why one woman went to medical school at 69
  • Visitors to this private space station won’t be wearing shorts and T-shirts
  • 2026 NFL Draft Round 1 grades: Rams get a C for Ty Simpson pick; Giants earn high marks – The Athletic – The New York Times
  • After using this HP laptop, I get why its ‘boring’ design is preferred by business users
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Cybersecurity»CISA Adds Two Actively Exploited Roundcube Flaws to KEV Catalog
Cybersecurity

CISA Adds Two Actively Exploited Roundcube Flaws to KEV Catalog

primereportsBy primereportsFebruary 22, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
CISA Adds Two Actively Exploited Roundcube Flaws to KEV Catalog
Share
Facebook Twitter LinkedIn Pinterest Email


Ravie LakshmananFeb 21, 2026Vulnerability / Patch Management

CISA Adds Two Actively Exploited Roundcube Flaws to KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Roundcube webmail software to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

The vulnerabilities in question are listed below –

  • CVE-2025-49113 (CVSS score: 9.9) – A deserialization of untrusted data vulnerability that allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php. (Fixed in June 2025)
  • CVE-2025-68461 (CVSS score: 7.2) – A cross-site scripting vulnerability via the animate tag in an SVG document. (Fixed in December 2025)
Cybersecurity

Dubai-based cybersecurity company FearsOff, whose founder and CEO, Kirill Firsov, was credited with discovering and reporting CVE-2025-49113, said attackers have already “diffed and weaponized the vulnerability” within 48 hours of public disclosure of the flaw. An exploit for the vulnerability was subsequently made available for sale on June 4, 2025.

Firsov also noted that the shortcoming can be triggered reliably on default installations, and that it had been hidden in the codebase for over 10 years.

There are no details on who is behind the exploitation of the two Roundcube flaws. But multiple vulnerabilities in the email software have been weaponized by nation-state threat actors like APT28 and Winter Vivern.

Federal Civilian Executive Branch (FCEB) agencies are to remediate identified vulnerabilities by March 13, 2026, to secure their networks against the active threat.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleNous Research’s NousCoder-14B is an open-source coding model landing right in the Claude Code moment
Next Article Ilia Malinin returns to Olympic ice a changed skater – The Washington Post
primereports
  • Website

Related Posts

Cybersecurity

‘Scattered Spider’ Member ‘Tylerb’ Pleads Guilty – Krebs on Security

April 23, 2026
Cybersecurity

Cloudsmith Raises $72 Million in Series C Funding

April 23, 2026
Cybersecurity

Google brings instant email verification to Android, no OTP needed

April 23, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Global Resources Outlook 2024 | UNEP

December 6, 20258 Views

The D Brief: DHS shutdown likely; US troops leave al-Tanf; CNO’s plea to industry; Crowded robot-boat market; And a bit more.

February 14, 20265 Views

German Chancellor Merz faces difficult mission to Israel – DW – 12/06/2025

December 6, 20254 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Geopolitics
  • Popular Now
  • Artificial Intelligence
  • Cybersecurity
  • Crypto
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • OpenAI announces GPT-5.5, its latest artificial intelligence model
  • OpenAI’s new Privacy Filter runs on your laptop so PII never hits the cloud
  • Wildfires in Florida after dry winter and spring lead to drought across US | Drought
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.