CVE-2024-42009Active Exploitation(roundcube / webmail)

HIGHCVSS 9.3 · CRITICALCISA KEV

Exploitation observed; activity peaked at 8 mentions and remains active

Immediate actions

  • Patch roundcube webmail systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php.

7.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-06-30. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-79

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • webmail

Threat summary

  • Active exploitation appears in 14 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 19 mentions across 7 observed days

What's happening

  • Active exploitation reported across 14 signals
  • Exploit tool or code specified in 3 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 11 signals
  • General: 3 classified signals
  • Peaked 4d ago at 8 mentions (2026-07-07); latest day: 1
  • 19 total mentions across 7 days

Affected systems

Vendors
Products
webmail

Deep dive

Activity timeline19 mentions / 7d
02468Mentions · 2026-01-31: 1Mentions · 2026-03-12: 1Mentions · 2026-07-07: 8Mentions · 2026-07-08: 3Mentions · 2026-07-09: 3Mentions · 2026-07-10: 2Mentions · 2026-07-24: 1PoC Mentioned / Linked · 2026-07-07: 2Exploit Tool / Code · 2026-07-07: 1Exploit Tool / Code · 2026-07-08: 1Exploit Tool / Code · 2026-07-09: 1Active Exploitation · 2026-07-07: 8Active Exploitation · 2026-07-08: 3Active Exploitation · 2026-07-09: 3Patch / Workaround · 2026-01-31: 1Patch / Workaround · 2026-07-07: 2Patch / Workaround · 2026-07-08: 2Technical Details · 2026-01-31: 1Technical Details · 2026-07-07: 5Technical Details · 2026-07-08: 3Technical Details · 2026-07-09: 1Technical Details · 2026-07-24: 101-3103-1207-0707-0807-0907-1007-24
Signal classification4 categories
Active Exploitation
1473.7%
General
315.8%
Patch
15.3%
Exploit
15.3%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-01-311
Patch1
2026-03-121
General1
2026-07-078
Active Exploitation8
2026-07-083
Active Exploitation3
2026-07-093
Active Exploitation3
2026-07-102
General2
2026-07-241
Exploit1
Full discourse19 posts
  • blackorbird@blackorbird
    Exploit

    TA488(Void Blizzard、Laundry Bear) Targets Zimbra Mailservers with Half-Click Exploits https://www.proofpoint.com/us/blog/threat-insight/ta488-targets-zimbra-mailservers-half-click-exploits Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days from TA458 CVE-2025-27915: Zimbra (zero-day) CVE-2025-3929: mDaemon (zero-day) CVE-2023-43770: Roundcube (n-day) CVE-2024-42009: Roundcube (n-day) CVE-2026- 8496: SOGo (zero-day) https://www.proofpoint.com/us/blog/threat-insight/ta458-roundpress-exploits

    Post summary

    The post lists multiple zero‑day half‑click exploits targeting webmail services (Zimbra, mDaemon, Roundcube, SOGo) with CVE identifiers, but does not provide PoC code, patches, or evidence of active exploitation.

    0813299.1K
    43.8K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    Active Exploitation

    🔴 Çin bağlantılı siber sadırganlar, kritik Roundcube güvenlik açıklarını kullanarak ABD ve Kanada'daki üniversiteleri hedef aldı! Zincirleme saldırıda CVE-2024-42009 ve CVE-2025-49113 istismar edilerek yalnızca e-postanın görüntülenmesiyle başlayan süreç, mail sunucusunun ele geçirilmesine kadar gidebiliyor. Yani zararlı e-postanın Roundcube'da açılmasıyla kimlik bilgileri çalınabiliyor ve mail sunucusunda uzaktan kod çalıştırılabiliyor. Teknik olarak bu risk sadece bu ülkelerle sınırlı değil. Türkiye lokasyon sunucularda da Roundcube versiyonu eski olan / yamalanmamış olan sunucular için de benzer saldırılar düzenlendiği biliniyor. Eğer Roundcube sürümü sunucunuzda eskiyse, acilen en yeni sürüme güncellemelisiniz.

    Post summary

    Red team alerts to active exploitation of Roundcube CVE-2024-42009 and CVE-2025-49113 via email-based chain attacks targeting universities in the US, Canada, and Turkey, urging immediate software updates.

    021721.6K
    2.2K followersView on X
  • Canadian Centre for Cyber Security@cybercentre_ca
    General

    #CyberAlert | Update: Roundcube Webmail vulnerabilities CVE-2024-42009 and CVE-2025-49113 https://www.cyber.gc.ca/en/alerts-advisories/vulnerability-impacting-roundcube-webmail-cve-2025-49113 https://t.co/fyi0kpLXFO

    Post summary

    The tweet links to a Canadian cyber alert about Roundcube Webmail vulnerabilities CVE‑2024‑42009 and CVE‑2025‑49113 but provides no additional technical or exploit information.

    01030737
    34.0K followersView on X
  • PurpleOps@PurpleOps_io
    Active Exploitation

    a china-aligned crew (UNK_MassTraction) is quietly exploiting two roundcube webmail bugs, CVE-2024-42009 and CVE-2025-49113, to get into US and canadian university mail servers. the targeting is the tell: physics and engineering departments, the research inboxes. this is espionage via webmail, not smash-and-grab. running since may.

    Post summary

    A China‑aligned group, UNK_MassTraction, is actively exploiting Roundcube webmail CVEs CVE‑2024‑42009 and CVE‑2025‑49113 against U.S. and Canadian universities, specifically targeting physics and engineering research inboxes since May.

    11020168
    608 followersView on X
  • cyber_updates_365@CyberUpdates365
    Active Exploitation

    🚨 Chinese hackers are actively exploiting Roundcube Webmail (CVE-2024-42009)! 🛑 A stored XSS flaw lets APTs steal your emails & session cookies just by viewing a message. Full patch & IOC guide 👇 https://cyberupdates365.com/roundcube-cve-2024-42009-chinese-hackers-exploit/ #CyberSecurity #InfoSec #latestnews #USA

    Post summary

    The post reports that Chinese APT actors are actively exploiting a stored XSS flaw in Roundcube Webmail (CVE‑2024‑42009), and provides a link to a patch and IOC guide.

    0003090
    16 followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    Chinese-linked UNK_MassTraction exploits CVE-2024-42009 (Roundcube XSS) to deploy IceCube stealer, then chains CVE-2025-49113 to drop SquareShell or VShell backdoor on university mail servers. Patch Roundcube now. #DFIR_Radar https://t.co/k0os84I0Dq

    Post summary

    Chinese-linked actors exploit Roundcube XSS CVE‑2024‑42009 to deploy IceCube stealer and then chain CVE‑2025‑49113 to drop SquareShell or VShell backdoors on university mail servers; a patch for Roundcube is now available.

    10000215
    1.7K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    Chinese-aligned UNK_MassTraction targeted US 🇺🇸 and Canadian 🇨🇦 university physics and engineering departments via CVE-2024-42009 (Roundcube XSS). #DFIR_Radar https://t.co/wzolgsz9eJ

    Post summary

    Chinese‑aligned UNK_MassTraction reportedly targeted U.S. and Canadian university physics and engineering departments using the Roundcube XSS vulnerability CVE‑2024‑42009, indicating active exploitation in the wild.

    10000154
    1.7K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    Chinese 🇨🇳 UNK_MassTraction chained CVE-2024-42009 and CVE-2025-49113 in Roundcube to compromise university mail servers, dropping VShell backdoors and webshells. Opening a single email triggers the exploit, no user interaction beyond that. #DFIR_Radar https://t.co/gbOySIo39u

    Post summary

    Chinese actors are actively exploiting CVE-2024-42009 and CVE-2025-49113 in Roundcube, compromising university mail servers via a single email and installing VShell backdoors and webshells.

    10000190
    1.7K followersView on X
  • SoEmailSecurity@Soemailsecurity
    Active Exploitation

    Universities' Roundcube webmail hacked via CVE-2024-42009 flaw, what's your email security plan? Check your email for vulnerabilities with a free scan at http://soemailsecurity.com, can you afford to wait? #emailsecurity #universityhacks #cyberthreats

    Post summary

    The post claims universities were hit by a Roundcube webmail hack using CVE‑2024‑42009, prompting a call to scan for vulnerabilities.

    1000051
    68 followersView on X
  • ByteSec1401 Efshagari@Leila97726926
    Active Exploitation

    Recent activity labelled 'UNK_MassTraction' is a cross scripting malware that exploits CVE-2024-42009, which affects RoundCube, has been attributed to Chinese actors. RoundCube itself is an IMAP email client used by educational institutions. The exploit has targeted both Canadian and U.S. universities, specifically on individuals that are working on astrophysics or particle physics. The way this malware is delivered is through Javascript, which is executed in the victim's browser. The credentials are then harvested and used to access mailservers through webshell or a running VShell backdoor. #Cybersecurity #Malware #CVE #Roundcube #China https://www.proofpoint.com/us/blog/threat-insight/one-email-closer-edge-unkmasstraction-physics-exploitation?utm_source=twitter&utm_medium=social_organic

    Post summary

    CVE‑2024‑42009 is being actively exploited by the UNK_MassTraction malware against RoundCube, targeting Canadian and U.S. universities, but no patch or mitigation information is provided.

    1000078
    320 followersView on X
  • Cybersecurity News Alerts@secureblognews
    Active Exploitation

    🔍 How dangerous is Roundcube CVE-2024-42009? Attackers run malicious JavaScript in the victim's browser to silently steal inbox data, contacts & session tokens with zero logs. 😱 See the attack chain 👇 https://cyberupdates365.com/roundcube-cve-2024-42009-chinese-hackers-exploit/ #AppSec #TechNews #cyberupdates365

    Post summary

    The post highlights that Roundcube CVE‑2024‑42009 is being used in real‑world attacks by running malicious JavaScript to stealthily exfiltrate inbox data, contacts, and session tokens.

    0001067
    29 followersView on X
  • Alone@alodotne
    General

    @the_real_egg_f @ProtonMail I'm confused? A webmail client is better than the actual email service it self?! CVE-2025-68461 CVE-2025-49113 CVE-2025-68460 CVE-2024-42009 CVE-2024-37385 CVE-2023-5631 CVE-2021-44026 CVE-2020-12641 CVE-2017-16651

    Post summary

    The tweet simply lists a series of CVE identifiers without any additional context, evidence of exploitation, or remediation guidance.

    10000174
    54 followersView on X
  • Centre canadien pour la cybersécurité@centrecyber_ca
    General

    #CyberAlerte | Vulnérabilités de Roundcube Webmail CVE-2024-42009 et CVE-2025-49113 https://www.cyber.gc.ca/fr/alertes-avis/vulnerabilite-touchant-courriel-web-roundcube-cve-2025-49113 https://t.co/dk1r5jLKjx

    Post summary

    A Canadian cyber alert cites two Roundcube Webmail CVEs, but the tweet provides only identifiers and a link, with no PoC, exploit, active use, patch info, or technical details.

    00000126
    3.7K followersView on X
  • Meridian Group@MeridianEU
    Active Exploitation

    Suspected China-aligned cluster targets US and Canadian universities via #Roundcube exploit chain: CVE-2024-42009 (CVSS 9.3) triggered by viewing a crafted email, chained with CVE-2025-49113 (CVSS 9.9) deserialization for RCE. Focus on research-value departments. https://t.co/VpIUy2GfQ8

    Post summary

    The tweet alleges that a China‑aligned cluster is actively exploiting Roundcube via two high‑severity CVEs against universities, but provides no PoC, exploit code, patch, or detailed technical explanation beyond CVSS scores.

    0000047
    66 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows China-linked threat actors chained CVE-2024-42009 and CVE-2025-49113 to compromise Roundcube webmail servers at academic institutions. Attackers deployed IceCube stealer and SquareShell webshell, then moved laterally to exfiltrate research data. Runtime segmentation could have limited their internal pivoting across university networks. #ThreatIntel 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/hackers-exploit-roundcube-flaw-to-spy-on-academic-researchers-2026

    Post summary

    China-linked threat actors exploited CVE-2024-42009 and CVE-2025-49113 to compromise Roundcube webmail servers at academic institutions, deploying IceCube stealer and SquareShell webshell for lateral movement and data exfiltration.

    0000064
    1.9K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    China-aligned threat actors exploited CVE-2024-42009 in Roundcube webmail to steal credentials from university staff via malicious JavaScript. Attackers then moved laterally across campus networks to exfiltrate sensitive research data. Runtime segmentation could help contain such post-compromise pivoting. #ThreatIntel 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/suspected-china-aligned-hackers-exploit-roundcube-flaws-against-universities-2026

    Post summary

    The message confirms active exploitation of CVE-2024-42009 in Roundcube; attackers used malicious JavaScript to capture credentials and pivot laterally across university networks.

    0000052
    1.9K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows UNK_MassTraction exploiting chained Roundcube vulnerabilities to compromise university mail servers. Attackers deployed webshells via CVE-2024-42009 and CVE-2025-49113, then moved laterally to exfiltrate physics and engineering research data. Runtime segmentation helps contain such post-compromise activity. #ThreatIntel 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/china-espionage-roundcube-exploit-universities-2026

    Post summary

    The report details active exploitation of Roundcube vulnerabilities (CVE-2024-42009 and CVE-2025-49113) by attackers deploying webshells to exfiltrate research data from university mail servers.

    0000063
    1.9K followersView on X
  • TECHEPAGES@techepages
    Active Exploitation

    🚨 A suspected China-aligned threat cluster, tracked by Proofpoint as UNK_MassTraction, is exploiting Roundcube webmail flaws (CVE-2024-42009 and CVE-2025-49113) against physics and engineering departments at U.S. and Canadian universities; merely opening a malicious email triggers the XSS exploit, harvesting credentials, 2FA data, and cookies via the IceCube payload. ⚠️ The infection chain deploys the SquareShell web shell or the Go-based VShell tool for persistent access, then wipes sessions to erase forensic evidence. Defenders should act now: 🔹 Patch Roundcube installations immediately as the campaign targets known N-day vulnerabilities 🔹 Defend mail servers as rigorously as VPN concentrators and other edge devices

    Post summary

    The post reports an active exploitation campaign against university mail systems using CVE‑2024‑42009 and CVE‑2025‑49113, recommends patching immediately, and details tools employed for persistence.

    0000061
    19 followersView on X
  • Nonchalant Sec@RotateKeys
    Patch

    Multiples vulnérabilités dans Roundcube (09 août 2024) — Le 4 août 2024, Roundcube a publié des correctifs concernant les vulnérabilités critiques CVE-2024-42008 et CVE-2024-42009 affectant son serveur de courriel. Ces vulnérabilités permettent des injections de code indirecte ht

    Post summary

    Roundcube released patches for CVE-2024-42008 and CVE-2024-42009, which allow indirect code injection in its mail server.

    0000078
    2 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Approundcubewebmail---

Explore more