Roundcube email bug can let attackers hijack inboxes
A serious bug in Roundcube Webmail lets attackers steal email accounts and hide on university servers. Attackers use this to break into bigger university networks, especially in physics and engineering research.
- Report priority
- Critical
- Fix
- Fixed in 1.5.8, 1.6.8
- Affected versions
- before 1.5.8; 1.6.0 to before 1.6.8
- Targets
- Roundcube Webmail
How it works
Attackers send specially crafted email requests to Roundcube Webmail that trick it into leaking account credentials and letting them install hidden backdoors.
What to do
Check the installed webmail version. This advisory applies to versions older than 1.5.8 or 1.6.0 to before 1.6.8.
Update webmail to 1.5.8 or 1.6.8 or newer. Then verify the installed version.
Technical details
Since May 2026, a suspected China-aligned threat cluster named UNK_MassTraction has been exploiting Roundcube mailservers at physics and engineering departments of US and Canadian universities. The campaigns exploit multiple n-day vulnerabilities including CVE-2024-42009 and CVE-2025-49113 to steal credentials and deploy either a webshell called SquareShell or the VShell backdoor into server memory. The actor uses an initial cross-site scripting vulnerability to execute JavaScript, then deploys IceCube stealer to harvest authentication material before pivoting server-side through deserialization exploits.
The operators deliberately crafted their infection chain with mature tooling to avoid detection, using Roundcube servers as pivot points to enter target networks. The targeting focuses on departments with national security ties or those studying astrophysics and particle physics.
Severity breakdown
- Attack vector Network Requires network access to the vulnerable service
- Attack complexity Low Low complexity under the assessed conditions
- Privileges required None Attacker needs no account or login
- User interaction Required Requires another user to take an action
- Scope Changed Impact crosses a security authority boundary
- Confidentiality impact High Sensitive data can be exposed with serious impact
- Integrity impact High Protected data can be changed with serious impact
- Availability impact None No availability impact
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N Open in FIRST.org calculatorReferences
- github.com · releases Release Notes
- github.com · 1.5.8 (tag) Release Notes
- github.com · 1.6.8 (tag) Release Notes
- thehackernews.com · suspected-china-aligned-hackers-exploit.html third party advisory TheHackerNews
- roundcube.net · security-updates-1.6.8-and-1.5.8 Vendor Advisory
- sonarsource.com · government-emails-at-risk-critical-cross-site-scripting-vulnerability-in-roundcube-webmail Technical Description Third Party Advisory
- cisa.gov · known-exploited-vulnerabilities-catalog US Government Resource
- nvd.nist.gov · CVE-2024-42009 us government resource vdb entry
- tenable.com · CVE-2024-42009 third party advisory vdb entry
- cvefeed.io · CVE-2024-42009 third party advisory vdb entry
- osv.dev · CVE-2024-42009 vdb entry
- nvd.nist.gov · CVE-2025-49113 vdb entry
- cybersecuritynews.com · hackers-exploit-roundcube-n-day-flaws Cyber Security News
- ppl-ai-file-upload.s3.amazonaws.com · Hackers-Exploit-Roundcube-N-Day-Flaws-to-Steal-Credentials-and-Deploy-VShell.pdf Cyber Security News
- proofpoint.com · one-email-closer-edge-unkmasstraction-physics-exploitation Cyber Security News eSecurityPlanet
- any.run · threat-intelligence-feeds Cyber Security News
- esecurityplanet.com · china-aligned-hackers-exploit-roundcube-servers-at-universities eSecurityPlanet
- scworld.com · suspected-chinese-spies-target-universities-with-roundcube-exploit SC World