What is CVE-2026-74999?
CVE-2026-74999: A stored XSS vulnerability was discovered in the 'Add to address book' action in Roundcube Webmail versions before 1.6.18 and 1.7.x before 1.7.3. Affected users should update to the latest version immediately.
Azərbaycanca: CVE-2026-74999: Roundcube Webmail-in əvvəlki versiyalarında 'Ünvan kitabçasına əlavə et' funksiyasında saxlanılmış XSS zəifliyi aşkar edilib. Bu, 1.6.18 və 1.7.3-dən əvvəlki versiyalara təsir edir. İstifadəçilər dərhal ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of Roundcube Webmail are affected by CVE-2026-74999?
The vulnerability affects Roundcube Webmail versions before 1.6.18 and 1.7.x versions before 1.7.3.
How can users protect against CVE-2026-74999 exploitation?
Users should update Roundcube Webmail to the latest version immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.