Roundcube RCE: Dark web activity signals imminent attacks (CVE-2025-49113)Help Net Security·Feb 23, 10:54 UTC · Feb 23, 2026Vulnerability in the wildCVE-2025-49113CVE-2024-42009CVE-2025-6846160
Over 80,000 servers hit as roundcube RCE bug gets rapidly exploitedSecurity Affairs·Jun 11, 11:43 UTC · Jun 11, 2025VulnerabilityCVE-2025-4911360
Roundcube flaws allow easy email account compromise (CVE-2024-42009, CVE-2024-42008)Help Net Security·Jun 10, 06:52 UTC · Jun 10, 2025Vulnerability in the wildCVE-2024-42009CVE-2024-42008CVE-2024-42010+4 CVEs60
U.S. CISA adds Cisco ASA and FTD, and RoundCube Webmail bugs to its Known Exploited Vulnerabilities catalogSecurity Affairs·Oct 25, 07:40 UTC · Oct 25, 2024Exploit / PoC in the wildCVE-2024-20481CVE-2024-3738360
Suspected China-Aligned Hackers Exploit Roundcube Flaws Against UniversitiesThe Hacker News·Jul 8, 05:07 UTC · Jul 8, 2026VulnerabilityCVE-2024-42009CVE-2025-4911360
U.S. CISA adds RoundCube Webmail flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Feb 21, 11:19 UTC · Feb 21, 2026Exploit / PoC in the wildCVE-2025-49113CVE-2025-6846160
Winter Vivern APT exploited zero-day in Roundcube webmail software in recent attacksSecurity Affairs·Oct 26, 05:20 UTC · Oct 26, 2023Exploit / PoCCVE-2020-35730CVE-2022-27926CVE-2023-563160
Winter Vivern: Zero-Day XSS Exploit Targets Roundcube ServersInfosecurity Magazine·Oct 25, 17:00 UTC · Oct 25, 2023Exploit / PoCCVE-2020-35730CVE-2023-563160
Roundcube Webmail under fire: critical exploit found after a decadeSecurity Affairs·Jun 4, 11:35 UTC · Jun 4, 2025Exploit / PoCCVE-2025-4911360
Critical XSS bug in Roundcube Webmail allows attackers to steal emails and sensitive dataSecurity Affairs·Aug 7, 21:10 UTC · Aug 7, 2024VulnerabilityCVE-2024-42009CVE-2024-42008CVE-2024-4201060
Roundcube webmail XSS vulnerability exploited by attackers (CVE-2023-43770)Help Net Security·Feb 15, 11:46 UTC · Feb 15, 2024Vulnerability in the wildCVE-2023-43770CVE-2020-35730CVE-2021-4402660
CISA adds Roundcube Webmail Persistent XSS bug to its Known Exploited Vulnerabilities catalogSecurity Affairs·Feb 12, 18:54 UTC · Feb 12, 2024Exploit / PoC in the wildCVE-2023-43770CVE-2020-3573060
Roundcube webmail zero-day exploited to spy on government entities (CVE-2023-5631)Help Net Security·Oct 25, 00:00 UTC · Oct 25, 2023Exploit / PoCCVE-2023-5631CVE-2020-35730CVE-2022-2792660
Critical 10-Year-Old Roundcube Webmail Bug Allows Authenticated Users Run Malicious CodeThe Hacker News·Jun 9, 12:15 UTC · Jun 9, 2025Exploit / PoC in the wildCVE-2025-49113CVE-2024-3738360
Roundcube XSS flaw exploited to steal credentials, email (CVE-2024-37383)Help Net Security·Oct 22, 00:00 UTC · Oct 22, 2024VulnerabilityCVE-2024-3738360
U.S. CISA adds RoundCube Webmail and Erlang Erlang/OTP SSH server flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jun 10, 13:34 UTC · Jun 10, 2025Exploit / PoC in the wildCVE-2025-32433CVE-2024-4200960
APT28 hacked Roundcube email servers of Ukrainian entitiesSecurity Affairs·Jun 21, 19:20 UTC · Jun 21, 2023Threat actorCVE-2020-35730CVE-2020-12641CVE-2021-44026+1 CVEs60
CISA Adds Erlang SSH and Roundcube Flaws to Known Exploited Vulnerabilities CatalogThe Hacker News·Jun 12, 05:02 UTC · Jun 12, 2025Exploit / PoC in the wildCVE-2025-32433CVE-2024-42009CVE-2025-3102260
Russia-Aligned TAG-70 Targets European Government and Military Mail Servers in New Espionage CampaignRecorded Future·Aug 22, 00:00 UTC · Aug 22, 2025Threat actorCVE-2023-2339760
Espionage group uses webmail server zeroThe Record·Oct 25, 12:08 UTC · Oct 25, 2023Threat actorCVE-2023-5631CVE-2020-3573060
Roundcube Webmail Flaws Allow Hackers to Steal Emails and PasswordsThe Hacker News·Aug 7, 13:29 UTC · Aug 7, 2024VulnerabilityCVE-2024-42008CVE-2024-42009CVE-2024-42010+1 CVEs60
Alert: CISA Warns of Active 'Roundcube' Email AttacksThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2024Advisory in the wildCVE-2023-4377060
BlueDelta Exploits Ukrainian Government Roundcube Mail Servers to Support Espionage ActivitiesRecorded Future·Aug 21, 00:00 UTC · Aug 21, 2025Threat actorCVE-2020-35730CVE-2023-23397CVE-2020-12641+1 CVEs60
CISA Adds Two Actively Exploited Roundcube Flaws to KEV CatalogThe Hacker News·Feb 21, 07:21 UTC · Feb 21, 2026Exploit / PoC in the wildCVE-2025-49113CVE-2025-6846160
Russia-Linked APT28 Exploited MDaemon ZeroThe Hacker News·May 15, 00:00 UTC · May 15, 2025Threat actor in the wildCVE-2020-12641CVE-2020-35730CVE-2021-44026+3 CVEs60
Suspected Chinese espionage group used a Roundcube exploit chain to burrow into universitiesCyberScoop·Jul 7, 09:00 UTC · Jul 7, 2026Threat actorCVE-2024-42009CVE-2025-4911360
Russia-aligned hackers target European and Iranian embassies in new espionage campaignThe Record·Feb 17, 01:36 UTC · Feb 17, 2024Threat actor in the wildCVE-2023-4377060
⚡ Weekly Recap: Chrome 0-Days, Router Botnets, AWS Breach, Rogue AI Agents & MoreThe Hacker News·Mar 15, 00:00 UTC · Mar 15, 2026Malware in the wildCVE-2026-3909CVE-2026-3910CVE-2026-3913+40 CVEs260
Russian Espionage Operation Targets Organizations Tied to Ukraine WarInfosecurity Magazine·May 16, 11:15 UTC · May 16, 2025Threat actorCVE-2024-11182CVE-2023-4377060
Nation State Hackers Exploiting ZeroThe Hacker News·Oct 26, 03:42 UTC · Oct 26, 2023Exploit / PoCCVE-2020-35730CVE-2023-563160
Pro-Russia hackers target inboxes with 0Ars Technica · Security·Oct 25, 22:21 UTC · Oct 25, 2023Exploit / PoCCVE-2023-563160
Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UACThe Hacker News·Jul 24, 06:50 UTC · Jul 24, 2026RansomwareCVE-2025-66376CVE-2026-8496CVE-2025-4911360
July 2026 CVE LandscapeRecorded Future·Aug 7, 00:00 UTC · Aug 7, 2026Ransomware in the wildCVE-2025-3248CVE-2008-4128CVE-2017-17215+78 CVEs160
Kremlin-linked hackers target webmail servers of Eastern European government agenciesThe Record·May 15, 14:13 UTC · May 15, 2025Exploit / PoC60
Security Affairs newsletter Round 425 by Pierluigi PaganiniSecurity Affairs·Jun 25, 15:26 UTC · Jun 25, 2023Ransomware in the wildCVE-2023-20178CVE-2023-20887CVE-2023-27992+4 CVEs60
From Phishing to Malware: AI Becomes Russia's New Cyber Weapon in War on UkraineThe Hacker News·Oct 9, 09:10 UTC · Oct 9, 2025MalwareCVE-2023-43770CVE-2024-37383CVE-2025-49113+2 CVEs60
Week in review: Microsoft fixes exploited zero-day, Mirai botnets target unpatched Wazuh serversHelp Net Security·Jun 15, 00:00 UTC · Jun 15, 2025Exploit / PoC in the wildCVE-2025-33053CVE-2025-24016CVE-2025-43200+1 CVEs60
Multi-national warning issued over Russia’s targeting of logistics, tech firmsCyberScoop·May 21, 18:41 UTC · May 21, 2025Exploit / PoC in the wildCVE-2023-23397CVE-2023-3883160
Spies hack high-value mail servers using an exploit from yesteryearArs Technica · Security·May 15, 00:00 UTC · May 15, 2025Exploit / PoCCVE-2023-4377060
Week in review: Fortinet patches critical FortiManager 0-day, VMware fixes vCenter Server RCEHelp Net Security·Oct 27, 00:00 UTC · Oct 27, 2024VulnerabilityCVE-2024-38812CVE-2024-38813CVE-2024-37383+3 CVEs60