Roundcube Webmail released security updates 1.6.18 and 1.7.3 to fix vulnerabilities affecting earlier versions of the platform. Public advisories from Roundcube, the Canadian Centre for Cyber Security, and Paraguay's CERT warned that deployments running versions prior to 1.6.18 in the 1.6.x branch and prior to 1.7.3 in the 1.7.x branch are exposed and should be updated.
The Canadian advisory AV26-793 said the issues affect Roundcube Webmail as of August 9 and urged administrators and users to review vendor guidance and apply the released patches. The coordinated notices indicate broad government and vendor attention to the flaws, with the vendor update serving as the primary remediation path for organizations using Roundcube in production.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security published advisory AV26-793 warning that Roundcube Webmail was affected by vulnerabilities and urging administrators and users to apply the available updates. The advisory referenced the newly released Roundcube security updates.
Roundcube released security updates 1.6.18 and 1.7.3 to address vulnerabilities in Roundcube Webmail. Versions prior to 1.6.18 and prior to 1.7.3 were identified as affected.
CERT-PY published a notice about vulnerabilities affecting Roundcube products. The reference indicates the notice was published on July 17, 2026.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecyber.gc.ca
Open sourceroundcube.net
Open sourcecert.gov.py
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.