Roundcube email bug can let attackers hijack inboxes

Published July 7, 2026 CVE-2024-42009

A serious bug in Roundcube Webmail lets attackers steal email accounts and hide on university servers. Attackers use this to break into bigger university networks, especially in physics and engineering research.

Report priority
Critical
Fix
Fixed in 1.5.8, 1.6.8
Affected versions
before 1.5.8; 1.6.0 to before 1.6.8
Targets
Roundcube Webmail

How it works

Attackers send specially crafted email requests to Roundcube Webmail that trick it into leaking account credentials and letting them install hidden backdoors.

What to do

Check the installed webmail version. This advisory applies to versions older than 1.5.8 or 1.6.0 to before 1.6.8.

Update webmail to 1.5.8 or 1.6.8 or newer. Then verify the installed version.

Technical details

Since May 2026, a suspected China-aligned threat cluster named UNK_MassTraction has been exploiting Roundcube mailservers at physics and engineering departments of US and Canadian universities. The campaigns exploit multiple n-day vulnerabilities including CVE-2024-42009 and CVE-2025-49113 to steal credentials and deploy either a webshell called SquareShell or the VShell backdoor into server memory. The actor uses an initial cross-site scripting vulnerability to execute JavaScript, then deploys IceCube stealer to harvest authentication material before pivoting server-side through deserialization exploits.

The operators deliberately crafted their infection chain with mature tooling to avoid detection, using Roundcube servers as pivot points to enter target networks. The targeting focuses on departments with national security ties or those studying astrophysics and particle physics.

Severity breakdown

  • Attack vector Network Requires network access to the vulnerable service
  • Attack complexity Low Low complexity under the assessed conditions
  • Privileges required None Attacker needs no account or login
  • User interaction Required Requires another user to take an action
  • Scope Changed Impact crosses a security authority boundary
  • Confidentiality impact High Sensitive data can be exposed with serious impact
  • Integrity impact High Protected data can be changed with serious impact
  • Availability impact None No availability impact
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N Open in FIRST.org calculator