VORANT. Threat Intelligence Sign in Get the full feed

Roundcube Webmail patches SSRF, XSS flaws

medium vulnerability

Roundcube Webmail versions before 1.6.17 and 1.7.2 contain multiple vulnerabilities including SSRF, XSS, and denial-of-service issues, patched by the vendor.

The French national cybersecurity agency (ANSSI/CERT-FR) issued an advisory covering multiple vulnerabilities in Roundcube Webmail, an open-source webmail client widely deployed by organizations to provide browser-based email access. The flaws affect Roundcube versions 1.6.x prior to 1.6.17 and 1.7.x prior to 1.7.2, and include a server-side request forgery (SSRF) vulnerability, a remote indirect code injection (stored/reflected XSS), a remote denial-of-service condition, and a security policy bypass.

The vendor released fixed versions (1.6.17 and 1.7.2) on July 5, 2026, addressed under CVE-2026-54432 and CVE-2026-54433. No evidence of active exploitation is mentioned in the advisory; this is a standard vendor patch notification. Organizations running affected Roundcube deployments should apply the updates promptly, as webmail interfaces are a common target for phishing-driven credential theft and lateral movement when left unpatched.

Mentioned in this report

Vulnerabilities CVE-2026-54432CVE-2026-54433

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0835

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free