DIRAS TAKE
Urgent: public exploit code exists for this Roundcube Webmail stored XSS and the attack can run in a victim's authenticated session via message preview, so prioritize upgrading or applying mitigations now.
What is CVE-2026-54433?
Attackers can execute JavaScript in the context of a logged-in Roundcube Webmail user and take over their session; this is CVE-2026-54433. The flaw affects Roundcube Webmail 1.6.0 through before 1.6.17 and 1.7.0 through before 1.7.2. A malicious plain-text email crafted by an attacker triggers the vulnerability when the recipient previews or opens the message, allowing script execution inside the victim's authenticated session. The weakness is classified as CWE-79 (Cross-site Scripting).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Which versions of Roundcube Webmail are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 1.x | 1.6.0 – before 1.6.17 | 1.6.17 |
| 1.x | 1.7.0 – before 1.7.2 | 1.7.2 |
Is CVE-2026-54433 being exploited?
Public exploit code is available.
How to fix CVE-2026-54433
- Upgrade Roundcube Webmail to 1.6.17 or later, or 1.7.2 or later.
- If you cannot upgrade immediately, block or filter incoming suspicious plain-text email and disable automatic message previews.
- Restrict access to webmail to trusted networks or via VPN where feasible.
- Monitor webmail logs and user accounts for unusual activity and reset sessions for high-risk users after patching.
Frequently asked questions
Is CVE-2026-54433 being actively exploited?
Public exploit code is available for CVE-2026-54433, indicating the vulnerability can be weaponized; there is no CISA Known Exploited Vulnerabilities listing for it as of the provided date.
Which Roundcube Webmail versions are affected by CVE-2026-54433?
Roundcube Webmail versions 1.6.0 up to but not including 1.6.17, and 1.7.0 up to but not including 1.7.2, are affected.
Is there a patch for CVE-2026-54433?
Yes. The issue is fixed in Roundcube Webmail 1.6.17 and 1.7.2.
Does CVE-2026-54433 require authentication?
The JavaScript executes in the context of an authenticated Roundcube Webmail session when a user previews or opens the crafted message, so it impacts logged-in users.
References
- nvd.nist.gov/vuln/detail/CVE-2026-54433
- cve.org/CVERecord?id=CVE-2026-54433
- roundcube.net/news/2026/07/05/security-updates-1.6.17-and-1.7.2
- All Roundcube CVEs on CVE Radar
- CVEs published in September 2026