logo

Roundcube Webmail Security Updates Patches Multiple Critical Vulnerabilities

ID: 59ce25e9-3bb4-5db7-baca-387a23b55ca3

STIX ID: report--59ce25e9-3bb4-5db7-baca-387a23b55ca3

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-03-24

Date Updated: 2026-04-21

Author: Abinaya

...
...

Roundcube Webmail 1.6.14 fixes multiple critical vulnerabilities across the 1.6.x branch — most notably a pre-auth arbitrary-file-write via unsafe deserialization that can lead to unauthenticated remote code execution, plus SSRF, information disclosure, an account password-change bypass enabling takeovers, IMAP injection combined with CSRF bypass, and several client-side XSS and privacy bypass issues; administrators are urged to back up systems and update immediately, with packages and signatures available on the project’s GitHub.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.