SophiaX
🔍
LIVE
· New victim: Portable Intelligence Inc www.portable-intelligence.com serviced by an IT company Computer... — blacknevas· New victim: Riker Danzig Scherer Hyland & Perretti — SilentRansomGroup· New victim: Hightech Signs — kairos· New victim: Riker Danzig LLP — SilentRansomGroup· New victim: gamaus.com — incransom· New KEV: CVE-2026-72898 · Metabase· New KEV: CVE-2026-20349 · Cisco· New KEV: CVE-2026-68820 · Microsoft· New KEV: CVE-2026-8037 · Progress· New KEV: CVE-2026-63077 · JetBrains· New victim: 3,981 new IOCs ingested in last 24h Portable Intelligence Inc www.portable-intelligence.com serviced by an IT company Computer... — blacknevas· New victim: Riker Danzig Scherer Hyland & Perretti — SilentRansomGroup· New victim: Hightech Signs — kairos· New victim: Riker Danzig LLP — SilentRansomGroup· New victim: gamaus.com — incransom· New KEV: CVE-2026-72898 · Metabase· New KEV: CVE-2026-20349 · Cisco· New KEV: CVE-2026-68820 · Microsoft· New KEV: CVE-2026-8037 · Progress· New KEV: CVE-2026-63077 · JetBrains· 3,981 new IOCs ingested in last 24h

CVE-2025-49113

⚡ CISA KEV
Published: Modified: Vendor: RoundcubeProduct: Webmail
CVSS v3
97.7%
EPSS
⚡ Added to KEV on 2026-02-20 · Federal agencies must remediate by 2026-03-13
RoundCube Webmail contains a deserialization of untrusted data vulnerability that allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php.
💣 Public Exploits1
From Exploit-DB
Roundcube 1.6.10 - Remote Code Execution (RCE)multiplewebapps2025-06-13
🔍 Sigma Detection Rules0
Rules tagged with this CVE
No Sigma rules tagged with this CVE.
🛠️ Patch Details1
Affected/fixed versions from threat intel reports
Roundcube Roundcube Webmailsource ↗
📰 Threat Intel Coverage1
Digest reports mentioning this CVE
Suspected Chinese Espionage Group Used Roundcube Exploit Chain to Target Universitieshawkeye2026-07-10
📎 References0
No reference URLs.