# Roundcube Webmail patches multiple flaws

Published: 2026-03-19 · Severity: medium
Canonical: https://vorant.io/reports/1f378ccb-d49c-5093-93e9-0383f44dcb17/roundcube-webmail-patches-multiple-flaws

> Roundcube fixed several vulnerabilities including SSRF, XSS, and data confidentiality issues across versions before 1.5.14, 1.6.14, and 1.7-rc5.

ANSSI (CERT-FR) issued an advisory covering multiple vulnerabilities in Roundcube Webmail affecting versions 1.5.x prior to 1.5.14, 1.6.x prior to 1.6.14, and 1.7.x prior to 1.7-rc5. The flaws allow an attacker to compromise data confidentiality, bypass security policies, perform server-side request forgery (SSRF), inject remote code indirectly via cross-site scripting (XSS), and conduct cross-site request forgery (CSRF) attacks.

Three CVEs are referenced (CVE-2026-35537, CVE-2026-35544, CVE-2026-35545). Roundcube published corresponding security updates on 18 March 2026. No evidence of active exploitation is mentioned in the advisory; administrators are advised to apply the vendor patches referenced in the bulletin.

## Mentioned in this report

- Vulnerabilities: CVE-2026-35537, CVE-2026-35544, CVE-2026-35545

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0320

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/1f378ccb-d49c-5093-93e9-0383f44dcb17/roundcube-webmail-patches-multiple-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
