CyberMax
Home › Exploited CVEs

Roundcube known exploited vulnerabilities

CISA KEV catalog 2026.09.25 (1,726 CVEs) with FIRST EPSS scores from 2026-09-27.

CISA lists 11 Roundcube CVEs as exploited in the wild. 2 were added in the last 12 months (latest 2026-02-20), and 0 are known to be used in ransomware campaigns.

Roundcube CVEs added to CISA KEV per year
2021: 1202112023: 4202342024: 3202432025: 1202512026: 220262

Year = when CISA added the CVE to the catalog (KEV started in November 2021).

Patch first: highest EPSS right now

EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.

Most affected Roundcube products

Webmail (7), Roundcube Webmail (4).

All Roundcube CVEs in KEV

CVEProductFlawAddedFederal dueEPSSRansomware
CVE-2025-68461WebmailRoundCube Webmail Cross-site Scripting2026-02-202026-03-1326.8%–
CVE-2025-49113WebmailRoundCube Webmail Deserialization of Untrusted Data2026-02-202026-03-1398.9%–
CVE-2024-42009WebmailRoundCube Webmail Cross-Site Scripting2025-06-092025-06-3082.9%–
CVE-2024-37383WebmailRoundCube Webmail Cross-Site Scripting (XSS)2024-10-242024-11-1473.3%–
CVE-2020-13965WebmailWebmail Cross-Site Scripting (XSS)2024-06-262024-07-1776.6%–
CVE-2023-43770WebmailWebmail Persistent Cross-Site Scripting (XSS)2024-02-122024-03-0463.7%–
CVE-2023-5631WebmailWebmail Persistent Cross-Site Scripting (XSS)2023-10-262023-11-1675.9%–
CVE-2021-44026Roundcube WebmailWebmail SQL Injection2023-06-222023-07-1369.9%–
CVE-2020-35730Roundcube WebmailWebmail Cross-Site Scripting (XSS)2023-06-222023-07-1332.7%–
CVE-2020-12641Roundcube WebmailWebmail Remote Code Execution2023-06-222023-07-1384.3%–
CVE-2017-16651Roundcube WebmailWebmail File Disclosure2021-11-032022-05-0345.7%–
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

Read next: Which CVEs to patch first this week · All vendors