Roundcube Webmail is a technology platform tracked across 8 threat clusters and 10 intelligence report mentions on ThreatCluster. First observed December 19, 2025; most recent activity July 10, 2026.
Roundcube Webmail is an open-source, web-based email client that provides a browser-based interface for managing email. Recent reports identify cross-site scripting (XSS) and information disclosure vulnerabilities in Roundcube that could allow attackers to run malicious scripts in a victim's browser and potentially compromise sessions or data, with Fedora advisories issuing mitigations for these issues, underscoring its significance as an attack surface in webmail deployments.
A suspected China-aligned threat group, tracked as UNK_MassTraction, has been exploiting vulnerabilities in Roundcube mail servers at U.S. and Canadian universities since May 2026. The campaign targets physics and…
Roundcube Webmail has been found vulnerable due to eight security flaws, four of which are rated high severity (CVE-2026-48842, CVE-2026-48843, CVE-2026-48844, CVE-2026-48848). Attackers can exploit these…
A Cross-Site-Scripting (XSS) vulnerability has been identified in Roundcube Webmail, allowing attackers to execute arbitrary scripts in the context of a user's session if they visit a malicious website. The…
On March 10, 2026, three critical vulnerabilities were published affecting Substance3D software. CVE-2026-21365 and CVE-2026-27219 both impact Substance3D - Painter versions 11.1.2 and earlier, exposing users to…
Two vulnerabilities in RoundCube Webmail have been added to the KEV Catalog, highlighting the risks associated with webmail services. The vulnerabilities pose potential exploitation opportunities for hackers, as noted…
Roundcube Webmail has issued critical security updates for vulnerabilities in versions 1.6 and 1.5 LTS. These flaws, including a Cross-Site Scripting (XSS) issue in SVG handling, could allow attackers to execute…
A critical Cross-Site Scripting (XSS) vulnerability has been identified in Roundcube Webmail, enabling attackers to track email opens by loading remote images. This flaw affects users who have set their preferences to…
Fedora 42 and 43 have reported vulnerabilities in RoundCube Webmail, specifically related to cross-site scripting (XSS) and information disclosure. Users of RoundCube, a browser-based multilingual IMAP client, are…