TTO-2026-0907-107 · September 7, 2026 PatchHigh Severity

Roundcube Webmail Patches Zero-Click Stored XSS and SSRF Bypass Across 12 Vulnerabilities

roundcube.netZero-click stored XSSSSRF bypass12 vulnerabilitiesVersions 1.6.19 and 1.7.4Sep 6 release

Summary

Roundcube Webmail released security updates 1.6.19 and 1.7.4 on September 6, 2026, addressing 12 vulnerabilities including a zero-click stored cross-site scripting flaw, a server-side request forgery bypass in the CSS proxy, multiple email header injection bugs, and a cross-user contact access issue. The zero-click nature of the lead XSS vulnerability means exploitation requires no user interaction beyond receiving and viewing a crafted email. No confirmed in-the-wild exploitation of these specific flaws has been reported at the time of publication.

Timeline

DateEvent
Sep 6, 2026Roundcube releases versions 1.6.19 and 1.7.4 addressing 12 security vulnerabilities
Sep 7, 2026No confirmed in-the-wild exploitation reported as of this bulletin

What Happened

The lead flaw is a zero-click stored XSS involving injection of TNEF MIME tags into attachment URLs. A malicious email can embed crafted MIME metadata causing attacker-controlled script to execute when a recipient opens or previews the message, without any click required. A second stored XSS affects the HTML editor when processing text/enriched MIME content.

An SSRF bypass in the CSS proxy allows hexadecimal IPv6-mapped IPv4 address representations to evade filtering, enabling server-side requests to internal network resources. Additional fixes address email header injection through subject fields, recipient display names, and identity organization fields; cross-user SQL address-book modification; multiple remote content blocking bypasses; and an is_local_url() validation bypass. Roundcube is widely deployed by hosting providers and bundled in Nextcloud installations. Administrators should update to 1.6.19 or 1.7.4 promptly.

Domain Intelligence

roundcube.net — 61.27

Score sits in the low-trust range. One threat intelligence source has flagged roundcube.net but the observation has not been independently corroborated; per WarmBadge's methodology, an unconfirmed single-source flag does not reduce the published score on its own.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 7, 2026