Multiple vulnerabilities in Roundcube (August 9, 2024)
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
On August 4, 2024, Roundcube released patches for critical vulnerabilities CVE-2024-42008 and CVE-2024-42009 affecting its email server. These vulnerabilities allow for indirect remote code injections (XSS) that can, for example, lead to the retrieval of...
CSIRTS triage
- What
- Roundcube has critical vulnerabilities that allow for indirect remote code injections (XSS).
- Who is affected
- Deployments of Roundcube email server are affected by these vulnerabilities.
- Urgency
- Remediation is urgent due to confirmed exploitation and the critical nature of the vulnerabilities.
- Action
- Users should apply the patches released on August 4, 2024.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Roundcube
Get an email when a new Roundcube advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/alerte/CERTFR-2024-ALE-010/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Elevated exploitation riskCVE-2024-4200835.9% 30-day exploitation probability — well above the norm. Schedule remediation this cycle. Riskier than 98% of all EPSS-scored CVEs.
- Exploitation confirmedCVE-2024-42009Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 99.6% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2024-42008 | coverage & exploitation status | NVD · CVE.org |
| CVE-2024-42009 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- criticalexploitedAL25-007 - Vulnerability impacting Roundcube Webmail – CVE-2025-49113 – Update 1cccs
- criticalexploitedCVE-2024-42009: RoundCube Webmail Cross-Site Scripting Vulnerabilitycisa-kev
Recent advisories for Roundcube
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[NEW] [high] Roundcube Webmail: Multiple vulnerabilitiescert-bund · 2026-08-18
- mediumCVE-2026-75010: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password …nvd · 2026-08-17
- mediumCVE-2026-75007: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject …nvd · 2026-08-17
- mediumCVE-2026-75006: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets…nvd · 2026-08-17
- mediumCVE-2026-75004: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could le…nvd · 2026-08-17
- mediumCVE-2026-75003: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attr…nvd · 2026-08-17
More from CERT-FR Alertes de sécurité
- unknownMultiple vulnerabilities in Microsoft Sharepoint (July 22, 2026)2026-07-22
- unknownMultiple vulnerabilities in WordPress (July 20, 2026)2026-07-20
- unknownMultiple vulnerabilities in Secure Mobile Access (July 15, 2026)2026-07-15
- unknown[Update] Vulnerability in Microsoft Exchange Server (May 15, 2026)2026-05-15
- unknownVulnerability in F5 BIG-IP Access Policy Manager (March 31, 2026)2026-03-31