Roundcube shipped a security update on September 6, 2026. The Roundcube security update patches 12 vulnerabilities across the 1.6 LTS and 1.7 branches. The fixes include a zero-click stored XSS, an SSRF bypass, and several email header injection flaws.
Why this matters
Roundcube is one of the most widely deployed open-source webmail clients. Many hosting providers and Nextcloud installs bundle it. So a single flaw can expose a large pool of mailboxes. The most alarming bug is a zero-click stored XSS, which needs no user click to fire.
How the attacks work
The Roundcube security update closes several injection paths. One zero-click stored XSS hides inside TNEF attachment handling. Another XSS abuses text/enriched content in the HTML editor.
Attackers could also forge mail headers. The advisory lists header injection through the subject field, the recipient display name, and an identity’s organization field. Separately, an SSRF bypass abused the CSS proxy using hex IPv6-mapped IPv4 addresses. Together, these flaws could enable spoofing and server-side request forgery.
Exploitation status
Roundcube credits outside researchers, including Zach Hanley of Horizon3.ai, for the reports. The project did not assign CVE IDs for this release. No public proof-of-concept exploit and no in-the-wild attacks have been confirmed so far.
Affected versions
All Roundcube 1.6.x and 1.7.x installations before 1.6.19 and 1.7.4 are affected. Nextcloud users should also check their bundled Roundcube package version.
Patch and mitigation steps
Update now, since the team calls both releases stable. Move to 1.7.4 on the current branch, or 1.6.19 on LTS. Read the official Roundcube advisory for the full fix list. As always, back up your data before you upgrade.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!