{"id":361557,"date":"2026-02-24T08:20:00","date_gmt":"2026-02-24T16:20:00","guid":{"rendered":"https:\/\/cms-articles.softonic.io\/es\/?p=411365"},"modified":"2026-02-24T08:20:09","modified_gmt":"2026-02-24T16:20:09","slug":"if-you-have-an-email-in-roundcube-be-careful-they-may-have-illegally-accessed-your-account","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/if-you-have-an-email-in-roundcube-be-careful-they-may-have-illegally-accessed-your-account\/","title":{"rendered":"If you have an email in Roundcube, be careful! They may have illegally accessed your account"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The recognized webmail platform Roundcube faces serious security threats, according to researchers and the Cybersecurity and Infrastructure Security Agency (CISA). <strong>The vulnerabilities, registered as CVE-2025-49113 and CVE-2025-68461, have been added to CISA&#8217;s Known Exploited Vulnerabilities catalog<\/strong>, indicating their severity. The first vulnerability, CVE-2025-49113, is a deserialization issue that has remained unresolved for nearly 10 years and has a severity score of 9.9.<\/p>\n\n\n<h2 class=\"wp-block-heading\">Cyber-errors<\/h2>\n\n\n<p class=\"wp-block-paragraph\">This flaw has caught the attention of attackers, especially due to the extensive use of Roundcube in sectors such as government and higher education institutions. In a report by the Shadowserver organization, <strong>it was revealed that approximately 84,000 instances of the software are vulnerable<\/strong>. Ryan Dewhurst, head of proactive threat intelligence at the firm watchTowr, highlighted that the popularity of Roundcube makes it an attractive target for hackers, especially because <em>&#8220;webmail services are a goldmine&#8221;<\/em>.<\/p>\n\n\n<p class=\"wp-block-paragraph\">The second vulnerability mentioned, CVE-2025-68461, is related to a cross-site scripting issue and was fixed in December 2025. <strong>Roundcube has urged its users to upgrade to versions that include the necessary fixes<\/strong> to mitigate these security risks.<\/p>\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/2\/2026\/02\/cube.jpg\" alt=\"\" class=\"wp-image-411367\" \/><\/figure>\n\n\n<p class=\"wp-block-paragraph\">The continuous exposure to these vulnerabilities and the constant focus of hackers, <strong>including those linked to governments, create an alarming landscape for Roundcube users<\/strong>. With the increase in cyberattacks, institutions must take proactive measures to secure their email platforms.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The recognized webmail platform Roundcube faces serious security threats, according to researchers and the Cybersecurity and Infrastructure Security Agency (CISA). The vulnerabilities, registered as CVE-2025-49113 and CVE-2025-68461, have been added to CISA&#8217;s Known Exploited Vulnerabilities catalog, indicating their severity. The first vulnerability, CVE-2025-49113, is a deserialization issue that has remained unresolved for nearly 10 years and has a severity score of 9.9. Cyber-errors This flaw has caught the attention of attackers, especially due to the extensive use of Roundcube in sectors such as government and in institutions [&#8230;]<\/p>\n","protected":false},"author":9317,"featured_media":361558,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":0},"categories":[1015],"tags":[5605,2216],"usertag":[],"vertical":[],"content-category":[],"class_list":["post-361557","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-ciberseguridad","tag-hackers"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/361557","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9317"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=361557"}],"version-history":[{"count":3,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/361557\/revisions"}],"predecessor-version":[{"id":361704,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/361557\/revisions\/361704"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/361558"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=361557"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=361557"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=361557"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=361557"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=361557"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=361557"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}