Roundcube vulnerabilities
5 CVEs tracked
Based on our reporting, Roundcube Webmail appears in a critical context focused on HTML/CSS sanitization and plugin security. Key events revolve around increasingly sophisticated SVG and CSS-based information disclosure (CVE-2026-75000, CVE-2026-75003, CVE-2026-75006) and privilege escalation or token leakage in specific plugin configurations (managesieve - CVE-2026-75004, password/modoboa - CVE-2026-75010). Defenders must prioritize immediate patching to versions 1.6.18 and 1.7.3, specifically monitoring for attacks targeting these 5 CVEs, and apply extra scrutiny to environments where the managesieve and password plugins are actively used.
Azərbaycanca: Hesabatlarımıza əsasən Roundcube Webmail, xüsusilə HTML/CSS sanitizasiyası və plagin təhlükəsizliyi ilə bağlı kritik kontekstdə görünür. Əsas hadisələr getdikcə daha çox SVG və CSS əsaslı məlumat sızması (CVE-2026-75000, CVE-2026-75003, CVE-2026-75006) və xüsusi plagin konfiqurasiyalarında (managesieve - CVE-2026-75004, password/modoboa - CVE-2026-75010) imtiyaz artımı və token sızması ətrafında cərəyan edir. Müdafiəçilər xüsusilə bu 5 CVE-ni hədəf alan hücumlara qarşı 1.6.18 və 1.7.3 versiyalarına təcili yeniləməyə, həmçinin `managesieve` və `password` plaginlərinin aktiv istifadə olunduğu mühitlərdə əlavə monitorinq tətbiq etməyə diqqət yetirməlidir.
This vendor's CVEs5
This hub is built from skopnix's own reporting on Roundcube: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.