CVE-2020-35730 — Roundcube Webmail
CISA KEVAs of 2025-11-04, CVE-2020-35730 is a MEDIUM-severity vulnerability in Roundcube Webmail, CVSS v3.1 6.1, EPSS 64.8% (98.4th percentile). It is listed in the CISA Known Exploited Vulnerabilities catalog (added 2023-06-22), with a US federal remediation deadline of 2023-07-13. Threadlinqs Intelligence links 2 tracked threat campaigns to CVE-2020-35730, most recently “Russia (GRU Unit 26165 / APT28) Runs Multi-Vector Surveillance, Intimidation, Sabotage and Cyber Espionage Campaign Against Europe's Ukraine Defence Supply Chain”.
Last updated: 2025-11-04
What is CVE-2020-35730?
An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcube_string_replacer.php.
The record classifies CVE-2020-35730 under weakness class CWE-79. Its CVSS v3 base vector states that the flaw is reachable remotely over the network, needs no prior authentication, needs a user to take an action first. 4 affected-product entries are recorded, across 3 vendors, listed below. The identifier was first published 2085 days ago.
Severity and exploitation probability
- CVSS v3.1 base score
- 6.1 — MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N - EPSS (FIRST)
- 64.8% probability of exploitation in the next 30 days, higher than 98.4% of all scored CVEs
- CISA KEV
- Listed since 2023-06-22, federal remediation deadline 2023-07-13
- Threadlinqs priority
- 9/10 — CISA KEV-listed, which Threadlinqs floors at 9
- Published
- 2020-12-28, last modified 2025-11-04
Is CVE-2020-35730 being exploited?
CISA added CVE-2020-35730 to the Known Exploited Vulnerabilities catalog on 2023-06-22, which means the agency holds evidence of exploitation in the wild; US federal civilian agencies had to remediate it by 2023-07-13 under BOD 22-01. It currently carries a trending score of 40 in the Threadlinqs vulnerability feed.
Affected products and versions
- Roundcube: Webmail
- Fedoraproject: Fedora 32, Fedora 33
- Debian: Linux 9.0
How to fix CVE-2020-35730
The record marks a vendor fix as available for CVE-2020-35730. Patch reference: https://github.com/roundcube/roundcubemail/compare/1.4.9...1.4.10. Vendor advisory: https://github.com/roundcube/roundcubemail/compare/1.4.9...1.4.10. Because CVE-2020-35730 is KEV-listed, US federal civilian agencies were required to apply the vendor fix, or stop using the product, by 2023-07-13. Apply the vendor fix referenced above to every affected product listed in this record, then confirm the running version against the vendor advisory.
Threat activity tracking CVE-2020-35730
2 tracked threats in the Threadlinqs corpus reference CVE-2020-35730, either in the campaign’s CVE list or as an indicator on the campaign record.
- Russia (GRU Unit 26165 / APT28) Runs Multi-Vector Surveillance, Intimidation, Sabotage and Cyber Espionage Campaign Against Europe's Ukraine Defence Supply Chain — HIGH · 2026-08-16
- APT28/UAC-0001 Sustained Cyber Espionage Against Ukraine & EU (2024-2026 New TTPs) — HIGH · 2026-02-12
Sources
Seeded from nvd and not yet processed by the Threadlinqs enrichment pipeline, so blank CVSS, EPSS or KEV fields above mean NOT MEASURED rather than measured-absent.
- bugs.debian.org
- github.com
- github.com (1.2)
- github.com (1.3)
- github.com (1.4)
- lists.fedoraproject.org
- lists.fedoraproject.org (HMLIZWKMTRCLU7KZLEQHELS4INXJ7X5Q)
- roundcube.net
- alexbirnberg.com
← all vulnerabilities · Markdown version · Threadlinqs Intelligence