Vulnerabilities & Exploits · Web App Attack
Roundcube Makes University Mail a Foothold A webmail inbox is becoming the entry point to the mail server itself, and that breaks the usual assumption that this is just a mailbox problem. In this campaign, opening a malicious Roundcube message can hand over browser-stored credentials and session material, then use that access to plant a webshell and keep coming back after the first message is gone.
Proofpoint says UNK_MassTraction has been chaining two patched Roundcube flaws against U.S. and Canadian university physics and engineering departments since May, with fewer than 10 victims identified so far and more possibly affected. The activity has targeted administrators and professors, used generic lures and compromised or spoofed senders, and is aimed at long-lived mail-server access rather than simple mailbox theft.
Even if the original phishing email is removed and passwords are reset, stolen session data can keep the foothold alive.
5 sources · Jul 10
NVD KEV
Known exploited · CISA KEV
CVSS 9.9 CRITICAL: roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because… EPSS 99% (100th percentile).
CISA federal remediation date Mar 13 · date passed
Timeline Sources Jul 10 CCCS Advisories
AL25-007 - Vulnerability impacting Roundcube Webmail – CVE-2025-49113 – Update 1 - Canadian Centre for Cyber Security
AL25-007 - Vulnerability impacting Roundcube Webmail – CVE-2025-49113 – Update 1
original Jul 8 BleepingComputer
Hackers exploit Roundcube flaw to spy on academic researchers
and Canadian universities to steal credentials and deploy backdoor malware.
original Jul 7 Infosecurity Magazine
Suspected Chinese Threat Group Targets Universities
A suspected Chinese threat cluster is exploiting Roundcube vulnerabilities to compromise university networks in the US and Canada
original Part of the PlainSec briefing for 2026-07-10
Every edition of this story: Roundcube Makes University Mail a Foothold
More from today
Vulnerabilities & Exploits · Web App Attack
Roundcube Makes University Mail a Foothold A webmail inbox is becoming the entry point to the mail server itself, and that breaks the usual assumption that this is just a mailbox problem. In this campaign, opening a malicious Roundcube message can hand over browser-stored credentials and session material, then use that access to plant a webshell and keep coming back after the first message is gone.
Proofpoint says UNK_MassTraction has been chaining two patched Roundcube flaws against U.S. and Canadian university physics and engineering departments since May, with fewer than 10 victims identified so far and more possibly affected. The activity has targeted administrators and professors, used generic lures and compromised or spoofed senders, and is aimed at long-lived mail-server access rather than simple mailbox theft.
Even if the original phishing email is removed and passwords are reset, stolen session data can keep the foothold alive.
5 sources · Jul 10
NVD KEV
Known exploited · CISA KEV
CVSS 9.9 CRITICAL: roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because… EPSS 99% (100th percentile).
CISA federal remediation date Mar 13 · date passed
Timeline Sources Jul 10 CCCS Advisories
AL25-007 - Vulnerability impacting Roundcube Webmail – CVE-2025-49113 – Update 1 - Canadian Centre for Cyber Security
AL25-007 - Vulnerability impacting Roundcube Webmail – CVE-2025-49113 – Update 1
original Jul 8 BleepingComputer
Hackers exploit Roundcube flaw to spy on academic researchers
and Canadian universities to steal credentials and deploy backdoor malware.
original Jul 7 Infosecurity Magazine
Suspected Chinese Threat Group Targets Universities
A suspected Chinese threat cluster is exploiting Roundcube vulnerabilities to compromise university networks in the US and Canada
original Part of the PlainSec briefing for 2026-07-10
Every edition of this story: Roundcube Makes University Mail a Foothold
More from today