VENDOR

Roundcube vulnerabilities: CVEs, exploitation and patches

Every Roundcube CVE reviewed by Diras Labs analysts, newest first, with exploitation status and fixes.

  1. CVE-2026-75003
    Roundcube Webmail SVG url() bypass lets crafted images leak data Roundcube Webmail ·
    • PATCH AVAILABLE
    CRITICAL 9.8
  2. CVE-2026-62643
    Roundcube Webmail CSS sanitization SSRF and information disclosure Roundcube Webmail ·
    • PATCH AVAILABLE
    CRITICAL 10
  3. CVE-2026-54433
    Roundcube Webmail stored XSS zero-click via crafted email Roundcube Webmail ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 10
3 CVEs · page 1 of 1