{
"$type": "site.standard.document",
"bskyPostRef": {
"cid": "bafyreigytwdwx6qisdtadtsarfb4x4w4txlpo66hzortd4tmdfev6csr2y",
"uri": "at://did:plc:6wtxqaikjf62unmnajbfbq5v/app.bsky.feed.post/3mfivako44fz2"
},
"coverImage": {
"$type": "blob",
"ref": {
"$link": "bafkreiawtegtnyszdw3aqadaoej7tk22i2w6ccigzhmldymo5ncnmze4ky"
},
"mimeType": "image/webp",
"size": 90306
},
"path": "/cisa-adds-two-roundcube-vulnerabilities-to-known-exploited-list/",
"publishedAt": "2026-02-22T14:49:57.000Z",
"site": "https://vpncentral.com",
"tags": [
"News",
"CISA Adds Two Roundcube Vulnerabilities to Known Exploited List",
"VPN Central"
],
"textContent": "CISA added two Roundcube webmail flaws to its Known Exploited Vulnerabilities catalog due to active attacks. Federal agencies must fix them by March 13, 2026. The bugs are CVE-2025-49113 and CVE-2025-68461. CVE-2025-49113 is a critical deserialization flaw in upload.php. It lets logged-in users run code remotely via the _from URL parameter. CVSS score sits at […]\n\nThe post CISA Adds Two Roundcube Vulnerabilities to Known Exploited List appeared first on VPN Central.",
"title": "CISA Adds Two Roundcube Vulnerabilities to Known Exploited List"
}