PHP · JULY 2026 · EARLY WARNING

Suspected China-Aligned Hackers Exploit Roundcube Flaws

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
CVE-2024-42009Severity: CRITICAL

A suspected China-aligned threat activity cluster appears to be exploiting Roundcube webmail software belonging to physics and engineering departments of U.S. and Canadian universities. The exploitation involves critical security flaws, such as CVE-2024-42009, to siphon credentials.

What happened

A suspected China-aligned threat activity cluster, tracked under the moniker UNK_MassTraction by Proofpoint, has reportedly been exploiting Roundcube webmail software at U.S. and Canadian universities since May 2026. The targeted departments include those with national security ties or involved in astrophysics and particle physics research. The exploitation involves critical security flaws, such as CVE-2024-42009, to siphon credentials. The attack begins with malicious emails sent from compromised accounts or spoofed domains, using generic lures. Opening these emails in a vulnerable Roundcube client triggers exploitation of a cross-site scripting flaw. The threat actor is believed to deploy web shells for persistent access or use a known post-exploitation tool called VShell.

Professional software engineers should assess their exposure by checking if their Roundcube installations are running any of the affected versions listed in the threat data. It is recommended to upgrade to the latest version of Roundcube and monitor for any suspicious activity. The primary sources should be consulted for the most current information and detailed technical insights.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If roundcube is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats