Vulnerabilities
Multiple Roundcube Flaws Expose Webmail Servers to RCE, SSRF, and Privilege Escalation
Roundcube Webmail has released critical updates patching several security vulnerabilities affecting 1.6.x and 1.7.x release lines. The flaws expose systems to remote code execution, server-side request forgery, privilege escalation, and cross-site scripting. Administrators are urged to update to Roundcube versions 1.6.18 or 1.7.3 immediately.
Critical Flaws Discovered in Roundcube Webmail
Maintainers of the Roundcube webmail client have issued security patches addressing a cluster of vulnerabilities that pose severe risks to mail server deployments. The security flaws allow attackers to perform remote code execution, trigger server-side request forgery (SSRF), escalate privileges, and bypass standard security policies.
Impact and Vulnerability Breakdown
Exploitation of these weaknesses could enable unauthorized attackers to gain unauthorized access to mail servers, compromise data confidentiality, and execute arbitrary code within target environments.
The advisory covers multiple tracking identifiers, including CVE-2026-74997, CVE-2026-74998, CVE-2026-74999, CVE-2026-75000, CVE-2026-75002, CVE-2026-75004, CVE-2026-75006, CVE-2026-75007, and CVE-2026-75010.
Affected Systems and Patch Guidance
Organizations running self-hosted Roundcube installations are advised to check their active versions. The impacted software versions include:
- Roundcube Webmail 1.6.x releases prior to version 1.6.18
- Roundcube Webmail 1.7.x releases prior to version 1.7.3
System administrators should apply the patches by updating installations to Roundcube 1.6.18 or 1.7.3 to prevent potential exploitation.