← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 17, 2026 · 12:37via CVEFeed

CVE-2026-74997 - Roundcube Webmail Markasjunk Plugin Remote Code Execution Vulnerability

Brief

CVE ID : CVE-2026-74997

Published : Aug. 17, 2026, 12:37 p. m.

  • 30 minutes ago

Description : In Roundcube Webmail before 1.

  • 18 and 1.
  • x before 1.
  • 3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder replacement values. This issue only affects Roundcube instances using the markasjunk plugin with its cmd_learn driver.

Severity: 8.8

  • HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed