Roundcube has released Webmail 1.6.18 and 1.7.3 to fix 11 security vulnerabilities, led by CVE-2026-74997, a high-severity remote code execution flaw in the markasjunk plugin’s cmd_learn driver. The bug, classified as CWE-78, affects Roundcube 1.6.x before 1.6.18 and 1.7.x before 1.7.3 and can be triggered through crafted placeholder replacement values, potentially allowing command execution on the mail server with impacts to confidentiality, integrity, and availability. Roundcube urged all production deployments to upgrade, and administrators were advised to disable the markasjunk plugin if it is not needed.
The security updates also address SSRF filter bypasses, remote content blocking bypass, LDAP filter injection, arbitrary Sieve script injection, IMAP command injection, stored XSS, HTML/CSS sanitization bypasses, and a modoboa password-driver issue that could leak an authentication token to a user-controlled host. Roundcube said the flaws could expose webmail environments to mail theft, persistence, and lateral movement if left unpatched, and recommended restricting outbound connectivity from Roundcube hosts in addition to applying the new releases.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
MITRE received CVE-2026-74997 on 2026-08-17 for the Roundcube Webmail markasjunk plugin remote code execution vulnerability. The flaw is classified as CWE-78 and carries a high-impact CVSS v3.1 vector of AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.
On 2026-08-09, Roundcube also patched LDAP filter injection, arbitrary Sieve script injection, IMAP command injection, stored XSS in the Add to address book action, and HTML/CSS sanitization bypasses. The same updates also fixed a password modoboa driver issue that could leak an authentication token to a user-controlled host.
In the 2026-08-09 releases, Roundcube fixed SSRF bypasses in local URL validation, including abuse of 100.64.0.0/10 and fe80::/10 address ranges and crafted nip.io or sslip.io hostnames. The issues were reported by Dmytro Ivanenko and Milan Hoppe.
The 2026-08-09 Roundcube security releases patched a remote code execution flaw in the markasjunk plugin's cmd_learn driver, reported by nept1337. The issue affects Roundcube 1.6.x before 1.6.18 and 1.7.x before 1.7.3 and could allow command execution through crafted placeholder replacement values.
On 2026-08-09, Roundcube released versions 1.6.18 and 1.7.3 as security updates for the 1.6 and 1.7 branches, recommending production installations upgrade. The releases fixed multiple recently reported vulnerabilities across the webmail platform.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
acn.gov.it
Open sourceheise.de
Open sourcecvefeed.io
Open sourcecybersecuritynews.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.