Roundcube Webmail patches SSRF, XSS flaws
Roundcube Webmail versions before 1.6.17 and 1.7.2 contain multiple vulnerabilities including SSRF, XSS, and denial-of-service issues, patched by the vendor.
The French national cybersecurity agency (ANSSI/CERT-FR) issued an advisory covering multiple vulnerabilities in Roundcube Webmail, an open-source webmail client widely deployed by organizations to provide browser-based email access. The flaws affect Roundcube versions 1.6.x prior to 1.6.17 and 1.7.x prior to 1.7.2, and include a server-side request forgery (SSRF) vulnerability, a remote indirect code injection (stored/reflected XSS), a remote denial-of-service condition, and a security policy bypass.
The vendor released fixed versions (1.6.17 and 1.7.2) on July 5, 2026, addressed under CVE-2026-54432 and CVE-2026-54433. No evidence of active exploitation is mentioned in the advisory; this is a standard vendor patch notification. Organizations running affected Roundcube deployments should apply the updates promptly, as webmail interfaces are a common target for phishing-driven credential theft and lateral movement when left unpatched.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0835
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free