Skip to content
Threat Feed

Vendor

Roundcube

8 briefs RSS
critical threat

TA488 Exploits Zimbra Mailservers with Half-Click Vulnerability CVE-2025-66376

Russia-aligned threat actor TA488 (Void Blizzard, Laundry Bear) exploited CVE-2025-66376, a critical XSS vulnerability in Zimbra Collaboration Suite webmail, for at least five months in 2025 via crafted emails to gain persistent access, exfiltrate user credentials, 2FA codes, and bulk emails from Ukrainian government and US defense industrial base targets.

PoC Zimbra Collaboration Suite +10 TA488 +2 espionage xss zimbra apt state-sponsored half-click cve-2025-66376
2r 9t 3c 7i updated
high advisory

Multiple Vulnerabilities in Roundcube Webmail (CVE-2026-54432, CVE-2026-54433)

Multiple vulnerabilities, including Server-Side Request Forgery (SSRF), Cross-Site Scripting (XSS), and Denial of Service (DoS), have been discovered in Roundcube Webmail versions 1.6.x prior to 1.6.17 and 1.7.x prior to 1.7.2, allowing remote attackers to impact service availability and potentially execute malicious code or access internal resources.

Roundcube Webmail < 1.6.17 +1 webmail vulnerability ssrf xss dos web-application
high advisory

Multiple Vulnerabilities in Roundcube Webmail

Multiple vulnerabilities in Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1 could lead to remote code execution, data confidentiality breaches, data integrity breaches, SSRF, and SQL Injection.

Roundcube Webmail < 1.6.16 +1 roundcube webmail vulnerability rce ssrf sqli
2r 3t
critical advisory

Multiple Vulnerabilities in Roundcube Webmail

Multiple vulnerabilities in Roundcube Webmail allow an attacker to perform SQL injection attacks, bypass security measures, manipulate data, disclose confidential information, obtain extended privileges, execute arbitrary code, or perform cross-site scripting attacks.

Roundcube Webmail roundcube webmail vulnerability sqli xss code execution
2r 3t
critical advisory

Roundcube Vulnerability Allows Remote Code Execution

A remote, authenticated attacker can exploit a vulnerability in Roundcube to execute arbitrary program code, potentially leading to complete system compromise.

Roundcube code-execution vulnerability webmail
2r 1t
high threat

FrostyNeighbor Targets Ukraine with Updated PicassoLoader Chain

The FrostyNeighbor threat actor is targeting Ukrainian governmental organizations with spearphishing emails containing malicious PDFs that deliver a JavaScript dropper (PicassoLoader) and ultimately a Cobalt Strike beacon.

PoC Cobalt Strike +8 FrostyNeighbor cyberespionage cobaltstrike picassoloader ukraine
2r 3t 5c 16i updated
medium advisory

Roundcube Vulnerabilities Leading to Cross-Site Scripting and Information Disclosure

Multiple vulnerabilities in Roundcube allow an attacker to perform a cross-site scripting attack and disclose confidential information.

Roundcube xss vulnerability
2r 1t 3c
high threat

APT28 Targeting Roundcube Webmail in Ukraine

APT28 (Fancy Bear) is actively targeting Roundcube webmail platforms to compromise government and defense email accounts, leveraging Roundcube's vulnerabilities and widespread use, primarily targeting Ukrainian entities in an activity tracked as Operation Roundish.

Roundcube Webmail APT28 +6 roundcube webmail ukraine exploitation
2r 3t