Roundcube known exploited vulnerabilities
CISA lists 11 Roundcube CVEs as exploited in the wild. 2 were added in the last 12 months (latest 2026-02-20), and 0 are known to be used in ransomware campaigns.
Year = when CISA added the CVE to the catalog (KEV started in November 2021).
Patch first: highest EPSS right now
EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.
- CVE-2025-49113 (Webmail): EPSS 98.9%, added 2026-02-20
- CVE-2020-12641 (Roundcube Webmail): EPSS 84.3%, added 2023-06-22
- CVE-2024-42009 (Webmail): EPSS 82.9%, added 2025-06-09
- CVE-2020-13965 (Webmail): EPSS 76.6%, added 2024-06-26
- CVE-2023-5631 (Webmail): EPSS 75.9%, added 2023-10-26
Most affected Roundcube products
Webmail (7), Roundcube Webmail (4).
All Roundcube CVEs in KEV
| CVE | Product | Flaw | Added | Federal due | EPSS | Ransomware |
|---|---|---|---|---|---|---|
| CVE-2025-68461 | Webmail | RoundCube Webmail Cross-site Scripting | 2026-02-20 | 2026-03-13 | 26.8% | – |
| CVE-2025-49113 | Webmail | RoundCube Webmail Deserialization of Untrusted Data | 2026-02-20 | 2026-03-13 | 98.9% | – |
| CVE-2024-42009 | Webmail | RoundCube Webmail Cross-Site Scripting | 2025-06-09 | 2025-06-30 | 82.9% | – |
| CVE-2024-37383 | Webmail | RoundCube Webmail Cross-Site Scripting (XSS) | 2024-10-24 | 2024-11-14 | 73.3% | – |
| CVE-2020-13965 | Webmail | Webmail Cross-Site Scripting (XSS) | 2024-06-26 | 2024-07-17 | 76.6% | – |
| CVE-2023-43770 | Webmail | Webmail Persistent Cross-Site Scripting (XSS) | 2024-02-12 | 2024-03-04 | 63.7% | – |
| CVE-2023-5631 | Webmail | Webmail Persistent Cross-Site Scripting (XSS) | 2023-10-26 | 2023-11-16 | 75.9% | – |
| CVE-2021-44026 | Roundcube Webmail | Webmail SQL Injection | 2023-06-22 | 2023-07-13 | 69.9% | – |
| CVE-2020-35730 | Roundcube Webmail | Webmail Cross-Site Scripting (XSS) | 2023-06-22 | 2023-07-13 | 32.7% | – |
| CVE-2020-12641 | Roundcube Webmail | Webmail Remote Code Execution | 2023-06-22 | 2023-07-13 | 84.3% | – |
| CVE-2017-16651 | Roundcube Webmail | Webmail File Disclosure | 2021-11-03 | 2022-05-03 | 45.7% | – |
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.
Read next: Which CVEs to patch first this week · All vendors