# Roundcube Webmail patches SSRF and XSS flaws

Published: 2026-09-07 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/6ff270a5-7134-504f-a74b-5b4e04415c45/roundcube-webmail-patches-ssrf-and-xss-flaws

> ANSSI advisory details multiple Roundcube Webmail vulnerabilities enabling SSRF, remote XSS, and security policy bypass, fixed in 1.6.19 and 1.7.4.

ANSSI (French CERT) published an advisory covering multiple vulnerabilities in Roundcube Webmail affecting version branches 1.6.x prior to 1.6.19 and 1.7.x prior to 1.7.4. The flaws allow an attacker to perform server-side request forgery (SSRF), conduct indirect remote cross-site scripting (XSS), and bypass security policy controls within the webmail application. No exploitation in the wild is mentioned in the advisory, and no CVE identifiers are provided in the source text.

Roundcube is a widely deployed open-source webmail client, and vulnerabilities of this class (SSRF, XSS) are historically attractive to attackers targeting mail infrastructure for credential theft, internal network reconnaissance, or session hijacking. Organizations running affected Roundcube versions should apply the vendor's official patches referenced in the September 6, 2026 security bulletin as soon as possible. No indicators of compromise or active exploitation were disclosed in this advisory.

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1122

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/6ff270a5-7134-504f-a74b-5b4e04415c45/roundcube-webmail-patches-ssrf-and-xss-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
