Roundcube released security updates for its webmail software to fix multiple vulnerabilities affecting versions prior to 1.6.14, including a pre-authentication arbitrary file write tied to unsafe deserialization in the Redis/Memcache session handler and tracked externally as CVE-2026-35537. The updates in versions 1.5.14 and 1.6.14 also addressed a password change issue, an IMAP injection flaw with CSRF bypass, several remote image blocking bypasses, a fixed-position mitigation bypass, an XSS issue in HTML attachment preview, and an SSRF plus information disclosure weakness involving stylesheet links to local network hosts. Roundcube noted that 1.7 pre-release builds were also affected.
A follow-up release in versions 1.5.15 and 1.6.15 corrected regressions introduced by the earlier fixes and patched an additional cross-site issue described as an SVG Animate FUNCIRI attribute bypass, which could allow remote image loading through fill, filter, and stroke attributes. That flaw was reported by class_nzm and appears to be tracked as CVE-2026-35545, extending the remediation effort beyond the initial advisory as administrators were urged to move to the latest patched builds.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
On 2026-03-29, Roundcube released versions 1.5.15 and 1.6.15 to correct regressions introduced in 1.5.14 and 1.6.14. The follow-up update also fixed an additional cross-site issue involving an SVG Animate FUNCIRI attribute bypass, apparently tracked as CVE-2026-35545.
On 2026-03-18, Roundcube released versions 1.5.14 and 1.6.14 to fix multiple vulnerabilities in its webmail software, including issues also affecting 1.7 pre-release versions. The most serious flaw was a pre-authentication arbitrary file write caused by unsafe deserialization in the Redis/Memcache session handler, apparently tracked as CVE-2026-35537.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourceseclists.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.