Roundcube Webmail patches SSRF and XSS flaws
ANSSI advisory details multiple Roundcube Webmail vulnerabilities enabling SSRF, remote XSS, and security policy bypass, fixed in 1.6.19 and 1.7.4.
ANSSI (French CERT) published an advisory covering multiple vulnerabilities in Roundcube Webmail affecting version branches 1.6.x prior to 1.6.19 and 1.7.x prior to 1.7.4. The flaws allow an attacker to perform server-side request forgery (SSRF), conduct indirect remote cross-site scripting (XSS), and bypass security policy controls within the webmail application. No exploitation in the wild is mentioned in the advisory, and no CVE identifiers are provided in the source text.
Roundcube is a widely deployed open-source webmail client, and vulnerabilities of this class (SSRF, XSS) are historically attractive to attackers targeting mail infrastructure for credential theft, internal network reconnaissance, or session hijacking. Organizations running affected Roundcube versions should apply the vendor's official patches referenced in the September 6, 2026 security bulletin as soon as possible. No indicators of compromise or active exploitation were disclosed in this advisory.
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1122
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free