Roundcube Webmail — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
10
occurrences
First Seen
December 19, 2025
Last Seen
July 10, 2026

Roundcube Webmail is a technology platform tracked across 8 threat clusters and 10 intelligence report mentions on ThreatCluster. First observed December 19, 2025; most recent activity July 10, 2026.

Overview

Roundcube Webmail is an open-source, web-based email client that provides a browser-based interface for managing email. Recent reports identify cross-site scripting (XSS) and information disclosure vulnerabilities in Roundcube that could allow attackers to run malicious scripts in a victim's browser and potentially compromise sessions or data, with Fedora advisories issuing mitigations for these issues, underscoring its significance as an attack surface in webmail deployments.

Related Threat Clusters

  • Chinese Threat Group Exploits Roundcube Vulnerabilities in University Networks

    A suspected China-aligned threat group, tracked as UNK_MassTraction, has been exploiting vulnerabilities in Roundcube mail servers at U.S. and Canadian universities since May 2026. The campaign targets physics and…

    13 articles · Updated July 7, 2026
  • Roundcube Webmail Vulnerabilities Expose Systems to Malware Attacks

    Roundcube Webmail has been found vulnerable due to eight security flaws, four of which are rated high severity (CVE-2026-48842, CVE-2026-48843, CVE-2026-48844, CVE-2026-48848). Attackers can exploit these…

    5 articles · Updated May 27, 2026
  • Critical XSS Vulnerability in Roundcube Webmail Discovered

    A Cross-Site-Scripting (XSS) vulnerability has been identified in Roundcube Webmail, allowing attackers to execute arbitrary scripts in the context of a user's session if they visit a malicious website. The…

    2 articles · Updated June 30, 2026
  • Multiple Vulnerabilities Discovered in Substance3D Software

    On March 10, 2026, three critical vulnerabilities were published affecting Substance3D software. CVE-2026-21365 and CVE-2026-27219 both impact Substance3D - Painter versions 11.1.2 and earlier, exposing users to…

    178 articles · Updated March 11, 2026
  • RoundCube Webmail Vulnerabilities Identified and Cataloged

    Two vulnerabilities in RoundCube Webmail have been added to the KEV Catalog, highlighting the risks associated with webmail services. The vulnerabilities pose potential exploitation opportunities for hackers, as noted…

    1 article · Updated February 23, 2026
  • Roundcube Vulnerabilities Enable Malicious Script Execution

    Roundcube Webmail has issued critical security updates for vulnerabilities in versions 1.6 and 1.5 LTS. These flaws, including a Cross-Site Scripting (XSS) issue in SVG handling, could allow attackers to execute…

    3 articles · Updated December 19, 2025
  • Roundcube Webmail Vulnerability Allows Email Open Tracking

    A critical Cross-Site Scripting (XSS) vulnerability has been identified in Roundcube Webmail, enabling attackers to track email opens by loading remote images. This flaw affects users who have set their preferences to…

    23 articles · Updated February 9, 2026
  • Fedora 42 and 43 Roundcube Webmail XSS Vulnerabilities Addressed

    Fedora 42 and 43 have reported vulnerabilities in RoundCube Webmail, specifically related to cross-site scripting (XSS) and information disclosure. Users of RoundCube, a browser-based multilingual IMAP client, are…

    2 articles · Updated December 25, 2025

Recent Intelligence Reports

  • CVE-2025-49113 — nvd.nist.gov · July 10, 2026
  • Ubuntu 26.04 LTS Roundcube Important XSS Risk USN-8482 — Linuxsecurity · June 30, 2026
  • USN-8482-1: Roundcube Webmail vulnerability — Ubuntu · June 30, 2026
  • Security Updates 1.6.16 And 1.7.1 — roundcube.net · May 27, 2026
  • Roundcube webmail instances attackable with malware — Heise.De · May 27, 2026
  • You've got mail: Pair of RoundCube Webmail vulnerabilities added to KEV Catalog — Cybersecurityconnect.Au · February 23, 2026
  • Roundcube Webmail Vulnerability Let Attackers Track Email Opens — Cybersecuritynews · February 9, 2026
  • Fedora 42: roundcubemail Important XSS Fix with Advisory ID 2025 — Linuxsecurity · December 25, 2025

CVSS v3.1 Breakdown