TL;DR

CISA has identified and listed two actively exploited vulnerabilities affecting Roundcube, including CVE-2025-49113 with a CVSS score of 9.9.

What happened

["Two critical flaws in Roundcube webmail software have been added to CISA's KEV catalog"]

Why it matters for ops

['To alert administrators about actively exploited vulnerabilities', 'To encourage prompt patching and risk assessment']

Mitigation

  • Apply vendor patches immediately
  • Disable unnecessary services and features

Action items

  • Update Roundcube to the latest version
  • Review security configurations

Detection IOCs

  • Search for CVE-2025-49113 in system logs
  • Monitor network traffic for signs of exploitation attempts

Source link

https://thehackernews.com/2026/02/cisa-adds-two-actively-exploited.html