Summary
ESET researchers have identified an active attack campaign exploiting CVE-2026-44117, a critical stored cross-site scripting vulnerability in Roundcube Webmail that chains to server-side code injection, allowing attackers to execute arbitrary commands on the mail server. The vulnerability is rated CVSS 9.6. Attackers deliver malicious email messages to Roundcube users; when the recipient opens the message, the stored XSS payload executes in the browser session and subsequently triggers server-side code execution through a secondary flaw in Roundcube’s attachment handling. The campaign has targeted government ministries, foreign affairs offices, and non-governmental organizations across Eastern Europe. Roundcube has released patches in versions 1.6.10 and 1.5.8.
Timeline
| Date | Event |
|---|---|
| September 2026 | Active campaign exploiting CVE-2026-44117 against government and NGO targets; ESET captures and analyzes attack chain |
| Sep 23, 2026 | Roundcube releases patched versions 1.6.10 and 1.5.8; ESET publishes full technical analysis; BleepingComputer reports |
What Happened
CVE-2026-44117 is a stored cross-site scripting vulnerability triggered by a malicious email message. When a Roundcube user opens the crafted message, JavaScript embedded in the message body executes in the context of the user’s authenticated webmail session. The initial XSS payload harvests session tokens and cookies, but the campaign exploits a secondary flaw in Roundcube’s server-side attachment processing to escalate from browser-context JavaScript execution to server-side command execution on the underlying mail server. The combined chain allows an attacker who can send email to a Roundcube user to achieve full control over the mail server with no interaction beyond the recipient opening the message.
Roundcube is widely deployed as open-source webmail infrastructure in government agencies, NGOs, universities, and ISPs, particularly in Eastern Europe and the former Soviet states. ESET attributes the campaign to a known threat actor with prior history of targeting Eastern European diplomatic and government communications infrastructure. The attack requires no authentication and no user action beyond opening an email — Roundcube’s preview pane renders the malicious content automatically. Administrators should update to patched versions immediately and review mail server logs for indicators of compromise published by ESET.
Domain Intelligence
roundcube.net — 59.91
roundcube.net scores in the low-trust range at 59.91. Roundcube is the open-source webmail project whose software contains CVE-2026-44117. One threat intelligence source has flagged roundcube.net but the observation has not been independently corroborated.
The Trust Observatory · thetrustobservatory.com · September 24, 2026
The Trust Observatory · thetrustobservatory.com · September 8, 2026