Roundcube released versions 1.6.17 and 1.7.2 to address multiple security flaws in its webmail platform, including stored cross-site scripting, SSRF bypasses, password plugin issues tied to session-injected usernames, and denial-of-service conditions in TNEF message handling. The advisory highlights CVE-2026-54432, a stored XSS issue caused by an unescaped attachment MIME type on the attachment-validation warning page, and CVE-2026-54433, described as a zero-click stored XSS triggered during plain-text rendering.
The fixes also resolve an infinite loop in the TNEF decoder, expanding the impact beyond browser-side compromise to service disruption risks. A related Nuclei template update added detection coverage for CVE-2026-54433, reflecting active defender interest in identifying exposed Roundcube instances. Roundcube also warned that the unsupported 1.5 LTS branch has reached end of support and may remain vulnerable to these issues as well as earlier flaws fixed in 1.6.16 and 1.7.1.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
A GitHub pull request added and updated a Nuclei template entry for CVE-2026-54433, describing it as a critical zero-click stored XSS vulnerability in Roundcube Webmail. The visible discussion indicates follow-up edits to the associated YAML file on 2026-07-22.
In the same security notice, Roundcube warned that the unsupported 1.5 LTS branch had reached end of support and was likely affected by at least some of the newly addressed issues as well as earlier flaws fixed in 1.6.16 and 1.7.1. No specific date for the end-of-support event is provided in the source content.
On 2026-07-05, Roundcube released versions 1.6.17 and 1.7.2 to fix multiple vulnerabilities in its webmail software, including stored XSS, SSRF bypasses, password plugin issues, and TNEF-related denial-of-service and infinite loop flaws. The advisory explicitly mentions CVE-2026-54432 and CVE-2026-54433 among the fixed issues.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourceseclists.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.