← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 17, 2026 · 11:24via Cyber Security News

Roundcube 1.6.18 and 1.7.3 Released With Fix for RCE and SSRF Vulnerabilities

Brief

Roundcube has released versions 1.

  • 18 and 1.
  • 3 to address eleven security vulnerabilities affecting its webmail platform. The updates fix a remote code execution flaw, server-side request forgery bypasses, injection vulnerabilities, and stored cross-site scripting issues.

Administrators using Roundcube 1.

  • x or 1.
  • x should update as soon as possible. The most serious issue is a remote code execution vulnerability in the markasjunk plugin. The flaw affects the plugin’s cmd_learn driver, which is used to send messages to a spam-learning backend.

Security researcher nept1337 reported the issue. Successful exploitation could allow an attacker to execute commands within the affected Roundcube environment, posing a direct risk to the webmail server and potentially to other systems reachable from it.

Roundcube is widely used as a browser-based interface for email services.

Read more on Cyber Security News