Exploitation timeline
Threadlinqs has recorded 16 Roundcube CVEs published between and . The busiest month was 2026-05 (8 new CVEs). 8 of them (50%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.
Most exploited vulnerabilities
Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 16 of 16 tracked Roundcube CVEs.
- CVE-2020-12641critical 9.8KEVEPSS 93.1%
- CVE-2025-49113critical 9.9KEVEPSS 91.6%
- CVE-2023-5631medium 6.1KEVEPSS 83.4%
- CVE-2024-42009critical 9.3KEVEPSS 83.4%
- CVE-2023-43770medium 6.1KEVEPSS 80.4%
- CVE-2020-35730medium 6.1KEVEPSS 64.8%
- CVE-2021-44026critical 9.8KEVEPSS 64%
- CVE-2025-68461high 7.2KEVEPSS 6.8%
- CVE-2026-48842high 8.1EPSS 0.1%
- CVE-2026-48847low 3.7EPSS 0.1%
- CVE-2026-48844high 7.5EPSS 0%
- CVE-2026-48848high 7.2EPSS 0%
- CVE-2026-48849medium 4.4EPSS 0%
- CVE-2026-48845medium 6.5EPSS 0%
- CVE-2026-48846medium 6.5EPSS 0%
- CVE-2026-48843high 7.2EPSS 0%
Products affected
Threadlinqs normalises CPE and CNA product records across all 16 CVEs; 1 distinct Roundcube product is affected. The most frequently affected:
- Webmail 16 CVEs
Threat activity
10 tracked threat campaigns reference Roundcube products or exploit Roundcube CVEs:
- Lazarus Exploits CVE-2026-68820 Zero-Day via Malicious PDF Viewer in Operation Dream Job Against Defense IndustryCRITICAL
- Russia (GRU Unit 26165 / APT28) Runs Multi-Vector Surveillance, Intimidation, Sabotage and Cyber Espionage Campaign Against Europe's Ukraine Defence Supply ChainHIGH
- Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820 (AFD.sys) and Two Publicly Disclosed Zero-Days (CVE-2026-62832 "LegacyHive", CVE-2026-72971)CRITICAL
- Operation RoundPress: TA458 Deploys SpyPress Malware via Half-Click Webmail Zero-Days (CVE-2025-27915, CVE-2025-3929, CVE-2026-8496)CRITICAL
- UNK_MassTraction: China-Aligned Actor Exploits Roundcube CVE-2024-42009 & CVE-2025-49113 to Deploy IceCube Stealer and VShell Against University Physics DepartmentsHIGH
- UNK_MassTraction Exploits Roundcube XSS/Deserialization Flaws (CVE-2024-42009, CVE-2025-49113) to Spy on Academic ResearchersHIGH
- Roundcube Webmail 0-Click Stored XSS (CVE-2026-54432, CVE-2026-54433) — Versions Prior to 1.6.17 / 1.7.2HIGH
- Roundcube Webmail Pre-Auth SQL Injection in virtuser_query Plugin (CVE-2026-48842) — Patched in 1.6.16 / 1.7.1 Alongside 7 Other VulnerabilitiesHIGH
- RoundCube Webmail Active Exploitation — CVE-2025-49113 Deserialization RCE (CVSS 9.9) + CVE-2025-68461 XSS via SVG Animate Tag (CISA KEV)CRITICAL
- APT28/UAC-0001 Sustained Cyber Espionage Against Ukraine & EU (2024-2026 New TTPs)HIGH
Threat actors targeting Roundcube
Named threat actors attributed to campaigns that involve Roundcube products or CVEs, with the number of linked campaigns:
How to prioritise Roundcube patching
This order follows the data Threadlinqs holds for Roundcube, not a generic severity checklist:
- 8 of 16 Roundcube CVEs (50%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with CVE-2020-12641, CVE-2025-49113, CVE-2023-5631.
- Outside KEV, the highest EPSS scores are CVE-2026-48842 (0.1%), CVE-2026-48847 (0.1%), CVE-2026-48844 (0%).
- 4 CVEs score Critical and 5 High on CVSS v3 (maximum 9.9, average 7.2); sequence these after KEV and high-EPSS items.
- 1 CVE has a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.
About this data
Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.