LIVE · cybersecurity feed
Live wire
vendor

Roundcube

2 CVEs published in the last four months and 4 stories. Exploited flaws first.

Critical0
High2
Medium0
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-626437.2highwebmailIn Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization 54d ago
CVE-2026-544337.2highwebmailIn Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafte54d ago

Filter the full tracker by Roundcube

Our coverage of Roundcube

roundcubehigh

MassTraction Exploits Roundcube Flaws at US, Canadian Universities

A threat group known as UNK_MassTraction, believed to be linked to China, is exploiting vulnerabilities in Roundcube webmail to gain unauthorized access to sensitive research mail servers at universities in the United States and Canada. The attackers are reportedly stealing user sessions to achieve this access.

roundcubehigh

Suspected Chinese Threat Group Targets Universities via Vulnerable Roundcube Servers

A sophisticated threat group, believed to be operating from China, is actively exploiting security weaknesses in Roundcube webmail servers. Their objective is to gain unauthorized access to university networks across the United States and Canada, with the ultimate goal of stealing user login information.

CVE-2024-42009high

Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities

Researchers have identified a new cyberattack campaign targeting academic institutions in North America. The attackers, believed to be linked to China, are exploiting vulnerabilities within the Roundcube webmail system used by physics and engineering departments.

CVE-2024-42009high

Suspected Chinese espionage group used a Roundcube exploit chain to burrow into universities

A China-aligned espionage group has been observed targeting U.S. and Canadian universities, specifically in physics and engineering departments. The attackers exploited two vulnerabilities in the Roundcube email client (CVE-2024-42009 and CVE-2025-49113) to steal credentials and establish persistent access through webshells and backdoors. Proofpoint researchers identified the campaign, which appears to be ongoing, and noted that victims may not yet be aware of the compromise.