LIVE NEWS
  • SpaceX surges, but bigger days are ahead: TD Securities
  • UK Forces Seize Russian Shadow Fleet Oil Tanker
  • Elon Musk and co may relish march of the robots but there must be AI boundaries in the workplace | Heather Stewart
  • US strike kills leader of Venezuela’s Tren de Aragua gang, White House says
  • Wes Streeting plans to increase high-skilled immigration if he becomes PM | Wes Streeting
  • World Cup 2026: Biggest takeaways from Brazil-Morocco group match | World Cup 2026 News
  • CFTC Staff Give DCMs a Path to Convert Perpetual-Style Digital Commodity Futures Into True Perpetuals
  • After a month with a foldable phone, I can’t justify buying an ‘Ultra’ model anymore
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Cybersecurity»CISA Adds Two Actively Exploited Roundcube Flaws to KEV Catalog
Cybersecurity

CISA Adds Two Actively Exploited Roundcube Flaws to KEV Catalog

primereportsBy primereportsFebruary 22, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
CISA Adds Two Actively Exploited Roundcube Flaws to KEV Catalog
Share
Facebook Twitter LinkedIn Pinterest Email


Ravie LakshmananFeb 21, 2026Vulnerability / Patch Management

CISA Adds Two Actively Exploited Roundcube Flaws to KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Roundcube webmail software to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

The vulnerabilities in question are listed below –

  • CVE-2025-49113 (CVSS score: 9.9) – A deserialization of untrusted data vulnerability that allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php. (Fixed in June 2025)
  • CVE-2025-68461 (CVSS score: 7.2) – A cross-site scripting vulnerability via the animate tag in an SVG document. (Fixed in December 2025)
Cybersecurity

Dubai-based cybersecurity company FearsOff, whose founder and CEO, Kirill Firsov, was credited with discovering and reporting CVE-2025-49113, said attackers have already “diffed and weaponized the vulnerability” within 48 hours of public disclosure of the flaw. An exploit for the vulnerability was subsequently made available for sale on June 4, 2025.

Firsov also noted that the shortcoming can be triggered reliably on default installations, and that it had been hidden in the codebase for over 10 years.

There are no details on who is behind the exploitation of the two Roundcube flaws. But multiple vulnerabilities in the email software have been weaponized by nation-state threat actors like APT28 and Winter Vivern.

Federal Civilian Executive Branch (FCEB) agencies are to remediate identified vulnerabilities by March 13, 2026, to secure their networks against the active threat.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleNous Research’s NousCoder-14B is an open-source coding model landing right in the Claude Code moment
Next Article Ilia Malinin returns to Olympic ice a changed skater – The Washington Post
primereports
  • Website

Related Posts

Cybersecurity

After a month with a foldable phone, I can’t justify buying an ‘Ultra’ model anymore

June 14, 2026
Cybersecurity

Ex-school district employee jailed for hacks on former employer

June 13, 2026
Cybersecurity

Claude Fable 5 Doesn’t Change the Mythos Security Story

June 13, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Paxton’s win over Cornyn sets up high-stakes Texas clash with Talarico

May 28, 202616 Views

Global Resources Outlook 2024 | UNEP

December 6, 202510 Views

Texas Democrat Talarico claims voting laws are rigged ahead of Paxton race

May 28, 20269 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Geopolitics
  • Popular Now
  • Artificial Intelligence
  • Cybersecurity
  • Crypto
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • SpaceX surges, but bigger days are ahead: TD Securities
  • UK Forces Seize Russian Shadow Fleet Oil Tanker
  • Elon Musk and co may relish march of the robots but there must be AI boundaries in the workplace | Heather Stewart
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.