LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-68461: RoundCube Webmail Cross-site Scripting Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 20, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 13, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-68461 to its Known Exploited Vulnerabilities catalog on Feb 20, 2026, with a federal patch deadline of Mar 13, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

RoundCube Webmail contains a cross-site scripting vulnerability via the animate tag in an SVG document.

This vulnerability is a cross-site scripting issue in Roundcube Webmail. An attacker can supply an SVG document containing an animate tag that causes the application to execute attacker-controlled script in a victim's browser session. The flaw matters for organizations that run Roundcube because email clients are frequent targets for session hijacking and credential theft. Any user who views a malicious message or attachment could have their account actions performed without their knowledge.

How it works

The weakness is classified as CWE-79, improper neutralization of input during web page generation. In this case the application fails to sanitize the animate element inside an SVG document before rendering it in the browser. An attacker can therefore cause script to run in the context of the Roundcube origin, bypassing the same-origin policy for that session.

Technical readers should treat this as a stored or reflected XSS vector that originates from message content or attachment handling. No further exploit mechanics are provided in the available summary.

Am I affected? How to find it in your systems

How to remediate

If you can't patch immediately

If your data may have been exposed

Actively exploited cross-site scripting vulnerabilities have led to account takeovers and subsequent data exposure. Organizations can run a free exposure scan of their domains against known breach data to identify any already-compromised accounts.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedRoundcube · Webmail
WeaknessCWE-79
Added to CISA KEVFeb 20, 2026
Federal patch deadlineMar 13, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities