Multiples vulnérabilités dans Roundcube (06 juillet 2026)
Multiple vulnerabilities have been discovered in Roundcube Webmail, impacting versions 1.6.x (prior to 1.6.17) and 1.7.x (prior to 1.7.2). These vulnerabilities include denial-of-service attacks, server-side request forgery (SSRF), and remote cross-site scripting (XSS), allowing attackers to potentially disrupt service and inject malicious code.
A security advisory from CERT-FR details multiple vulnerabilities within the Roundcube Webmail application. These vulnerabilities allow for various attacks, including a denial-of-service attack, a server-side request forgery (SSRF) attack, and a remote cross-site scripting (XSS) attack. Specifically, versions 1.6.x are vulnerable prior to 1.6.17, and 1.7.x versions are vulnerable prior to 1.7.2. The advisory directs users to the Roundcube security updates bulletin for detailed information and patches. The vulnerabilities are linked to CVE identifiers: CVE-2026-54432, CVE-2026-54433, CVE-2026-62641, CVE-2026-62642, and CVE-2026-62643. The advisory points to a security update bulletin for further details and remediation steps.