Roundcube Webmail is an open-source, web-based email client that provides a browser-based interface for managing email.
Overview
Roundcube Webmail is an open-source, web-based email client that provides a browser-based interface for managing email. Recent reports identify cross-site scripting (XSS) and information disclosure vulnerabilities in Roundcube that could allow attackers to run malicious scripts in a victim's browser and potentially compromise sessions or data, with Fedora advisories issuing mitigations for these issues, underscoring its significance as an attack surface in webmail deployments.
Related Threat Clusters
-
Russian Hackers Exploit Zimbra Zero-Day for Espionage Campaign
Since July 2025, Russian state-backed hackers, known as Laundry Bear, have exploited a zero-click vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite to infiltrate Western government and commercial…
82 articles · Updated July 23, 2026 -
Chinese Threat Group Exploits Roundcube Vulnerabilities in University Networks
A suspected China-aligned threat group, tracked as UNK_MassTraction, has been exploiting vulnerabilities in Roundcube mail servers at U.S. and Canadian universities since May 2026. The campaign targets physics and…
14 articles · Updated July 7, 2026 -
APT28 Exploits Roundcube Vulnerabilities in Targeted Cyber Espionage Campaign
APT28 (Fancy Bear) has been linked to Operation Roundish, utilizing a comprehensive Roundcube exploitation toolkit against Ukrainian government targets. The toolkit, discovered in January 2026, includes XSS payloads, a…
3 articles · Updated July 23, 2026 -
Roundcube Webmail Vulnerabilities Expose Systems to Malware Attacks
Roundcube Webmail has been found vulnerable due to eight security flaws, four of which are rated high severity (CVE-2026-48842, CVE-2026-48843, CVE-2026-48844, CVE-2026-48848). Attackers can exploit these…
5 articles · Updated May 27, 2026 -
Critical XSS Vulnerability in Roundcube Webmail Discovered
A Cross-Site-Scripting (XSS) vulnerability has been identified in Roundcube Webmail, allowing attackers to execute arbitrary scripts in the context of a user's session if they visit a malicious website. The…
2 articles · Updated June 30, 2026 -
Critical RCE Vulnerability in BeyondTrust Software Requires Immediate Patching
BeyondTrust has issued a warning regarding a critical remote code execution (RCE) vulnerability in its Remote Support and Privileged Remote Access software. The flaw, tracked as CVE-2026-1731, allows unauthenticated…
1436 articles · Updated February 9, 2026 -
Roundcube Webmail Security Updates Address Vulnerabilities
On August 10, 2026, Roundcube announced security updates for versions 1.6 LTS and 1.7, specifically versions 1.6.18 and 1.7.3. These updates address recently reported security vulnerabilities affecting Roundcube Webmail…
4 articles · Updated August 10, 2026 -
RoundCube Webmail Vulnerabilities Identified and Cataloged
Two vulnerabilities in RoundCube Webmail have been added to the KEV Catalog, highlighting the risks associated with webmail services. The vulnerabilities pose potential exploitation opportunities for hackers, as noted…
1 article · Updated February 23, 2026 -
Roundcube Vulnerabilities Enable Malicious Script Execution
Roundcube Webmail has issued critical security updates for vulnerabilities in versions 1.6 and 1.5 LTS. These flaws, including a Cross-Site Scripting (XSS) issue in SVG handling, could allow attackers to execute…
3 articles · Updated December 19, 2025 -
Roundcube Webmail Vulnerability Allows Email Open Tracking
A critical Cross-Site Scripting (XSS) vulnerability has been identified in Roundcube Webmail, enabling attackers to track email opens by loading remote images. This flaw affects users who have set their preferences to…
23 articles · Updated February 9, 2026
Recent Intelligence Reports
- Roundcube security news archive — roundcube.net · August 11, 2026
- WinterVivern — www.welivesecurity.com · July 24, 2026
- CVE-2025-49113 — nvd.nist.gov · July 24, 2026
- Ubuntu 26.04 LTS Roundcube Important XSS Risk USN-8482 — Linuxsecurity · June 30, 2026
- USN-8482-1: Roundcube Webmail vulnerability — Ubuntu · June 30, 2026
- Security Updates 1.6.16 And 1.7.1 — roundcube.net · May 27, 2026
- Roundcube webmail instances attackable with malware — Heise.De · May 27, 2026
- You've got mail: Pair of RoundCube Webmail vulnerabilities added to KEV Catalog — Cybersecurityconnect.Au · February 23, 2026