# Roundcube Webmail patches SSRF, XSS flaws

Published: 2026-07-06 · Severity: medium
Canonical: https://vorant.io/reports/d827975c-e9b2-5718-a7f3-b330bb30eda0/roundcube-webmail-patches-ssrf-xss-flaws

> Roundcube Webmail versions before 1.6.17 and 1.7.2 contain multiple vulnerabilities including SSRF, XSS, and denial-of-service issues, patched by the vendor.

The French national cybersecurity agency (ANSSI/CERT-FR) issued an advisory covering multiple vulnerabilities in Roundcube Webmail, an open-source webmail client widely deployed by organizations to provide browser-based email access. The flaws affect Roundcube versions 1.6.x prior to 1.6.17 and 1.7.x prior to 1.7.2, and include a server-side request forgery (SSRF) vulnerability, a remote indirect code injection (stored/reflected XSS), a remote denial-of-service condition, and a security policy bypass.

The vendor released fixed versions (1.6.17 and 1.7.2) on July 5, 2026, addressed under CVE-2026-54432 and CVE-2026-54433. No evidence of active exploitation is mentioned in the advisory; this is a standard vendor patch notification. Organizations running affected Roundcube deployments should apply the updates promptly, as webmail interfaces are a common target for phishing-driven credential theft and lateral movement when left unpatched.

## Mentioned in this report

- Vulnerabilities: CVE-2026-54432, CVE-2026-54433

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0835

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/d827975c-e9b2-5718-a7f3-b330bb30eda0/roundcube-webmail-patches-ssrf-xss-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
