CVE-2020-12640Active Exploitation(opensuse / backports_sle)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for opensuse backports_sle systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plugin_api.php.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • backports_sle
  • leap
  • webmail

Threat summary

  • Active exploitation appears in 1 classified signals
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
backports_sleleapwebmail

3 versions affected across 3 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-09: 1Active Exploitation · 2026-03-09: 103-09
Signal classification1 categories
Active Exploitation
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • transilienceai@transilienceai
    Active Exploitation

    🚨 Roundcube Webmail Exploitation in the Wild: CVE-2020-12640 Analysis [CRITICAL] Mar 09, 2026 Checkout our Threat Intelligence Platform: https://threatintel.transilience.cloud https://threatintel.transilience.cloud #ThreatIntelligence #CyberSecurity #Innovation #LLM https://t.co/S5KDM7iKX3

    Post summary

    The tweet claims that CVE‑2020‑12640 in Roundcube Webmail has been exploited in the wild, but it offers no technical details, PoC, or patch information.

    0000072
    322 followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
Appopensusebackports_sle15.0--
Appopensusebackports_sle15.0--
OSopensuseleap15.1--
OSopensuseleap15.2--
Approundcubewebmail---

Explore more