AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence90%
Public exploitation · VTP factKEV
Assessment
CVE-2024-37383 allows cross-site scripting through SVG animate attributes in vulnerable Roundcube Webmail releases. CISA KEV lists the flaw as known exploited globally. Successful XSS can execute attacker-controlled script in a user's webmail session.
Why it matters
Webmail sessions can contain sensitive messages and user actions.
Exploitation requires a victim to interact with malicious content, according to the CVSS user-interaction prerequisite.
Evidence
1 record references and 0 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.
Uncertainties
No relevant current campaign details or exploit mechanism beyond the vulnerability description are available.
First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Next watchpoint
If you use Roundcube Webmail before 1.5.7 or 1.6.x before 1.6.7, upgrade to a fixed release.
Evidence confidence0%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
CISA KEV lists this vulnerability as known to be exploited globally.
02
EPSS is 0.73; this is predictive context, not exploitation evidence.
03
First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
02
Material change ledger
What changed
KEV ADDEDCISA KEV entry added
03
Claim provenance
Evidence and source independence
1publications detected
1underlying evidence chains
0 primary sources · 0 dependent secondary reports · 1 reports with unresolved independence. Repetition remains visible without multiplying confirmation.
04
Event history
Threat timeline
00:0024 Oct
KEV ADDED
CISA KEV entry added
CISA lists global known exploitation. This is not a VTP sensor observation.
05
Original publications
Source record
SecurityWeekPRESSUNKNOWN
Roundcube Webmail Vulnerability in Attackers’ Crosshairs
Tracked as CVE-2026-48842, the exploited bug is an SQL injection that can be exploited without authentication. The post Roundcube Webmail Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek .
First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.