Vulnerabilities & Exploits · Web App Attack

Roundcube Makes University Mail a Foothold

A webmail inbox is becoming the entry point to the mail server itself, and that breaks the usual assumption that this is just a mailbox problem. In this campaign, opening a malicious Roundcube message can hand over browser-stored credentials and session material, then use that access to plant a webshell and keep coming back after the first message is gone.

Proofpoint says UNK_MassTraction has been chaining two patched Roundcube flaws against U.S. and Canadian university physics and engineering departments since May, with fewer than 10 victims identified so far and more possibly affected. The activity has targeted administrators and professors, used generic lures and compromised or spoofed senders, and is aimed at long-lived mail-server access rather than simple mailbox theft.

Even if the original phishing email is removed and passwords are reset, stolen session data can keep the foothold alive.

5 sources · Jul 10

CVE-2025-49113

NVD KEV

Known exploited · CISA KEV

CVSS 9.9 CRITICAL: roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because… EPSS 99% (100th percentile).

CISA federal remediation date Mar 13 · date passed

Timeline

Sources

Part of the PlainSec briefing for 2026-07-08

Every edition of this story: Roundcube Makes University Mail a Foothold

More from today