A critical vulnerability in the widely used Roundcube Webmail allows authenticated attackers to execute arbitrary code remotely.
See also: RD Gateway UAF vulnerability allows RCE

The vulnerability, which was discovered through weaknesses in PHP object deserialization, affects all installations running versions 1.6.x and 1.5 of Roundcube, one of the most popular open-source webmail clients.
Security researcher firs0v reported the vulnerability, which led to the immediate release of fixes in versions 1.6.11 and 1.5.10 on June 1, 2025. Organizations around the world are urged to apply these updates immediately to prevent potential system breaches.
This new vulnerability has been labeled as a Post-Authentication Remote Code Execution (RCE) and exploits weaknesses in the PHP object deserialization mechanism within the Roundcube code. This vulnerability allows malicious users who have already obtained valid authentication credentials to execute arbitrary PHP code on the target server, which could lead to a complete system compromise
PHP object deserialization vulnerabilities occur when applications accept serialized data from untrusted sources without proper validation.
See also: Asus DriverHub flaws lead to RCE attacks
In the case of Roundcube, the vulnerability appears to arise from incorrect handling of serialized objects during session management or other data processing operations.

When an attacker creates malicious serialized payloads, they can exploit the deserialization process to create arbitrary PHP objects and invoke dangerous methods, ultimately leading to code execution.
The Common Vulnerability Scoring System (CVSS) rating for this type of vulnerability typically ranges between 7.0 and 9.0 , indicating high to critical severity.
The requirement for prior authentication slightly reduces the immediate risk, as attackers must first obtain a user's credentials through phishing, credential stuffing , or other techniques before they can exploit the vulnerability.
However, organizations using Roundcube installations run serious security risks if they delay installing the patches. The vulnerability affects all versions of Roundcube in the 1.6.x and 1.5.x, i.e. both the current stable version and the Long Term Support (LTS) version.
See also: Critical Erlang/OTP SSH RCE is very easy to exploit
The vulnerability once again demonstrates how critical it is to promptly apply security updates to open source software, especially to applications running in environments with sensitive data, such as webmail systems. Although the flaw requires prior authentication, its existence in such widespread software means that in cases where attackers manage to steal credentials (e.g. through phishing or password leaks), they can immediately gain control of the entire server.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: cybersecuritynews
