Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
RoundCube DOO

RoundCube DOO Vendor Cyber Rating & Cyber Score

roundcube.rs

RoundCube is a top-tier web development company that delivers innovative and scalable web and mobile applications tailored to the unique needs of diverse clients. Utilizing cutting-edge technologies and a powerful, collaborative team, we create efficient solutions that drive success. Based in Belgrade, RoundCube leverages the power of cloud technology to provide secure, reliable, and high-performance applications that help our clients achieve their goals and stay ahead of the competition. Partner with RoundCube and experience the difference that innovation and expertise can make.


RoundCube DOO A.I CyberSecurity Scoring

RoundCube DOO
Company Information
Website:https://roundcube.rs
Employees number:10
Number of followers:163
NAICS:5112
Industry Type:Software Development
Homepage:roundcube.rs
RoundCube DOO Risk Score (AI oriented)
Between 700 and 749
logo
RoundCube DOOSoftware Development
Updated:
29/03/2026
746/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
RoundCube DOO Global Score (TPRM)
xxxx
logo
RoundCube DOOSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

RoundCube DOO
RoundCube DOOModerate
Current Score
746Ba (MODERATE)
01000
2 incidents
-5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
747Before Incident
MAY 2026
746Before Incident
APRIL 2026
746Before Incident
MARCH 2026
746Before Incident
FEBRUARY 2026
750Before Incident
Vulnerability
08 Feb 2026RoundCube DOO
Roundcube: Roundcube Webmail Vulnerability Let Attackers Track Email Opens

Roundcube Patches Critical Privacy Bypass Vulnerability in Webmail Software

745After Incident
LOW-5
ROU1770638099
Roundcube Patches Critical Privacy Bypass Vulnerability in Webmail Software Roundcube, a widely used open-source webmail platform, has released urgent security updates to fix a privacy bypass flaw that allowed attackers to track email opens despite user settings blocking remote images. The vulnerability, disclosed by security researchers at NULL CATHEDRAL on February 8, 2026, affects all versions prior to 1.5.13 and 1.6.x versions before 1.6.13. The issue stemmed from a flaw in Roundcube’s HTML sanitizer, rcube_washtml, which failed to recognize the SVG element `<feImage>` as an image container. While the sanitizer blocked standard image tags (e.g., `<img>`), it treated `<feImage>` an SVG filter primitive that fetches external resources via the `href` attribute as a regular hyperlink. This allowed attackers to embed invisible 1×1 SVGs in emails, triggering automatic GET requests to attacker-controlled servers when the email was rendered. Exploiting this flaw enabled threat actors to: - Confirm active email addresses. - Log recipients’ IP addresses. - Fingerprint browsers and devices. The patch, implemented in commit 26d7677, updates the sanitizer’s regex logic to explicitly block `<feImage>` alongside other image-related tags. Administrators of self-hosted Roundcube instances are advised to upgrade to 1.5.13 or 1.6.13 to mitigate the risk.
INCIDENT DETAILS -
TYPE
Privacy Bypass
MOTIVATION
Reconnaissance, Email Tracking, IP Logging, Device Fingerprinting
IMPACT
Data Compromised: Email open tracking, IP addresses, browser/device fingerprintsSystems Affected: Roundcube webmail software (versions prior to 1.5.13 and 1.6.x before 1.6.13)
DATA BREACH
Type Of Data Compromised: Email open tracking data, IP addresses, device/browser fingerprintsSensitivity Of Data: Low to Medium (Non-PII but privacy-invasive)Data Exfiltration: GET requests to attacker-controlled serversPersonally Identifiable Information: No (unless combined with other attacks)
JANUARY 2026
750Before Incident
DECEMBER 2025
750Before Incident
NOVEMBER 2025
750Before Incident
OCTOBER 2025
750Before Incident
SEPTEMBER 2025
750Before Incident
AUGUST 2025
750Before Incident
JULY 2025
749Before Incident
JUNE 2025
752Before Incident
Vulnerability
01 Jun 2025RoundCube DOO
Roundcube

Critical RCE Flaw in Roundcube Webmail (CVE-2025-49113)

749After Incident
CRITICAL-3
ROU300060925
Over 84,000 Roundcube webmail installations are vulnerable to CVE-2025-49113, a critical remote code execution (RCE) flaw with a public exploit. The flaw, which impacts Roundcube versions 1.1.0 through 1.6.10, was patched on June 1, 2025. Hackers have reverse-engineered the patch to develop a working exploit, sold on underground forums. The vulnerability stems from unsanitized $_GET['_from'] input, enabling PHP object deserialization and session corruption. Although exploitation requires authentication, attackers claim valid credentials can be obtained via CSRF, log scraping, or brute-forcing. The high risk of exploitation and potential for data theft make the exposure of these instances a significant cybersecurity risk.
INCIDENT DETAILS -
TYPE
Remote Code Execution (RCE)
MOTIVATION
Data theft
IMPACT
Roundcube webmail installations

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for RoundCube DOO ?
?
What was RoundCube DOO's A.I Rankiteo Cyber Score in May 2026 ?
?
What was RoundCube DOO's A.I Rankiteo Cyber Score in April 2026 ?
?
What was RoundCube DOO's A.I Rankiteo Cyber Score in March 2026 ?
?
What was RoundCube DOO's A.I Rankiteo Cyber Score in February 2026 ?
?
What was RoundCube DOO's A.I Rankiteo Cyber Score in January 2026 ?
?
What was RoundCube DOO's A.I Rankiteo Cyber Score in December 2025 ?
?
What was RoundCube DOO's A.I Rankiteo Cyber Score in November 2025 ?
?
What was RoundCube DOO's A.I Rankiteo Cyber Score in October 2025 ?
?
What was RoundCube DOO's A.I Rankiteo Cyber Score in September 2025 ?
?
What was RoundCube DOO's A.I Rankiteo Cyber Score in August 2025 ?
?
What was RoundCube DOO's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on RoundCube DOO's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with RoundCube DOO ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view RoundCube DOO's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?