Summary
Roundcube Webmail released security updates 1.6.19 and 1.7.4 on September 6, 2026, addressing 12 vulnerabilities including a zero-click stored cross-site scripting flaw, a server-side request forgery bypass in the CSS proxy, multiple email header injection bugs, and a cross-user contact access issue. The zero-click nature of the lead XSS vulnerability means exploitation requires no user interaction beyond receiving and viewing a crafted email. No confirmed in-the-wild exploitation of these specific flaws has been reported at the time of publication.
Timeline
| Date | Event |
|---|---|
| Sep 6, 2026 | Roundcube releases versions 1.6.19 and 1.7.4 addressing 12 security vulnerabilities |
| Sep 7, 2026 | No confirmed in-the-wild exploitation reported as of this bulletin |
What Happened
The lead flaw is a zero-click stored XSS involving injection of TNEF MIME tags into attachment URLs. A malicious email can embed crafted MIME metadata causing attacker-controlled script to execute when a recipient opens or previews the message, without any click required. A second stored XSS affects the HTML editor when processing text/enriched MIME content.
An SSRF bypass in the CSS proxy allows hexadecimal IPv6-mapped IPv4 address representations to evade filtering, enabling server-side requests to internal network resources. Additional fixes address email header injection through subject fields, recipient display names, and identity organization fields; cross-user SQL address-book modification; multiple remote content blocking bypasses; and an is_local_url() validation bypass. Roundcube is widely deployed by hosting providers and bundled in Nextcloud installations. Administrators should update to 1.6.19 or 1.7.4 promptly.
Domain Intelligence
roundcube.net — 61.27
Score sits in the low-trust range. One threat intelligence source has flagged roundcube.net but the observation has not been independently corroborated; per WarmBadge's methodology, an unconfirmed single-source flag does not reduce the published score on its own.
The Trust Observatory · thetrustobservatory.com · September 7, 2026