Evidence used
- CISA confirms exploitation in the wild.
- A structured source references public exploit or proof-of-concept material.
- EPSS is 98.90% for the current model date.
BlackTreeCVE IntelligenceRoundcube · Webmail
CISA confirms exploitation in the wild and lists 2026-03-13 as the remediation due date.
Debian, ubuntu findings are scoped to the named distribution, release and source package. An absent finding does not mean a package is unaffected.
A published vendor fix does not prove that a matching update is enabled and installable on a particular asset. Confirm the local package candidate before scheduling remediation.
| Distribution release | Source package | Vendor state | Fixed version | Evidence |
|---|---|---|---|---|
| Debian trixietrixie · source | roundcube | Vendor fix publishedDebian records a fixed source-package version for this release. | 1.6.11+dfsg-1 | Debian Security Tracker ↗Source updated 5 Oct 2026 |
| Debian bookwormbookworm · source | roundcube | Vendor fix publishedDebian records a fixed source-package version for this release. | 1.6.5+dfsg-1+deb12u5 | Debian Security Tracker ↗Source updated 5 Oct 2026 |
| Debian forkyforky · source | roundcube | Vendor fix publishedDebian records a fixed source-package version for this release. | 1.6.11+dfsg-1 | Debian Security Tracker ↗Source updated 5 Oct 2026 |
| Debian sidsid · source | roundcube | Vendor fix publishedDebian records a fixed source-package version for this release. | 1.6.11+dfsg-1 | Debian Security Tracker ↗Source updated 5 Oct 2026 |
| Ubuntu 24.04 LTSnoble · standard archive | roundcube | Vendor fix publishedCanonical reports that a fixed source package version has been published. Repository candidate availability is not checked by BlackTree. | 1.6.6+dfsg-2ubuntu0.1 | Canonical Ubuntu Security ↗Source updated 5 Oct 2026 |
These OSV and GitHub advisory ranges apply only to the named package and ecosystem. A listed fixed version is not a universal product patch or proof that an update is installed.
| Ecosystem and package | Affected range | First fixed version | Evidence |
|---|---|---|---|
| composerroundcube/roundcubemail | < 1.5.10 | 1.5.10 | GitHub advisory ↗github reviewed aggregator · 20 Feb 2026 |
| composerroundcube/roundcubemail | >= 1.6.0, < 1.6.11 | 1.6.11 | GitHub advisory ↗github reviewed aggregator · 20 Feb 2026 |
CISA confirms exploitation in the wild and lists 2026-03-13 as the remediation due date.
Patch availableRoundCube Webmail contains a deserialization of untrusted data vulnerability that allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php.
RoundCube Webmail contains a deserialization of untrusted data vulnerability that allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php.
Attacker-influenced serialised data is reconstructed as trusted objects, which can invoke dangerous application behaviour.
An attacker operating through a network path may attempt exploitation with low privileges. If successful, the issue may execute code or commands in the affected security context.
RoundCube Webmail contains a deserialization of untrusted data vulnerability that allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php.
Attacker-influenced serialised data is reconstructed as trusted objects, which can invoke dangerous application behaviour.
An attacker operating through a network path may attempt exploitation with low privileges. If successful, the issue may execute code or commands in the affected security context.
CVSS severity, EPSS forecast probability, public exploit material and CISA-confirmed exploitation are separate signals.
CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2026-02-20.
A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.
CWE-502: Deserialization of Untrusted Data. The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HCommon Vulnerability Scoring System 3.1: the compact vector below is decoded into plain language.
Operational remediation based on structured source evidence.
Published 2 Jun 2025 · Last source change 21 Feb 2026, 04:56 UTC · CWE-502 · Deserialization of Untrusted Data
Core structured fields are present and their contributing authorities are shown above.