threat-intel Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities A China-aligned threat actor cluster, tracked as UNC5174 and linked to ShadowPad, has been exploiting vulnerabilities in Roundcube webmail software at U.S. and Canadian universities. The campaign leverages CVE-2024-42009 and CVE-2025-49113 to gain access, deploying tools like VShell and SquareShell to establish a footh… The Hacker News · Jul 7, 2026 High CVE-2024-42009CVE-2025-49113CHUSCAroundcubexsscve-2024-42009
vulnerability Multiples vulnérabilités dans Roundcube (19 mars 2026) Multiple vulnerabilities have been discovered in Roundcube Webmail, impacting versions 1.5.x through 1.5.14, 1.6.x through 1.6.14, and 1.7.x through 1.7-rc5. These flaws include data confidentiality breaches, SSRF attack… CERT-FR · Mar 19, 2026 Medium CVE-2026-35537CVE-2026-35544CVE-2026-35545roundcubevulnerabilitywebmail