VORANT. Threat Intelligence Sign in Get the full feed

Roundcube Webmail patches multiple flaws

medium vulnerability

Roundcube fixed several vulnerabilities including SSRF, XSS, and data confidentiality issues across versions before 1.5.14, 1.6.14, and 1.7-rc5.

ANSSI (CERT-FR) issued an advisory covering multiple vulnerabilities in Roundcube Webmail affecting versions 1.5.x prior to 1.5.14, 1.6.x prior to 1.6.14, and 1.7.x prior to 1.7-rc5. The flaws allow an attacker to compromise data confidentiality, bypass security policies, perform server-side request forgery (SSRF), inject remote code indirectly via cross-site scripting (XSS), and conduct cross-site request forgery (CSRF) attacks.

Three CVEs are referenced (CVE-2026-35537, CVE-2026-35544, CVE-2026-35545). Roundcube published corresponding security updates on 18 March 2026. No evidence of active exploitation is mentioned in the advisory; administrators are advised to apply the vendor patches referenced in the bulletin.

Mentioned in this report

Vulnerabilities CVE-2026-35537CVE-2026-35544CVE-2026-35545

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0320

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free