Roundcube Webmail patches multiple flaws
Roundcube fixed several vulnerabilities including SSRF, XSS, and data confidentiality issues across versions before 1.5.14, 1.6.14, and 1.7-rc5.
ANSSI (CERT-FR) issued an advisory covering multiple vulnerabilities in Roundcube Webmail affecting versions 1.5.x prior to 1.5.14, 1.6.x prior to 1.6.14, and 1.7.x prior to 1.7-rc5. The flaws allow an attacker to compromise data confidentiality, bypass security policies, perform server-side request forgery (SSRF), inject remote code indirectly via cross-site scripting (XSS), and conduct cross-site request forgery (CSRF) attacks.
Three CVEs are referenced (CVE-2026-35537, CVE-2026-35544, CVE-2026-35545). Roundcube published corresponding security updates on 18 March 2026. No evidence of active exploitation is mentioned in the advisory; administrators are advised to apply the vendor patches referenced in the bulletin.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0320
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free