securityonline.info 6 Sept 2026, 14:32 UTC

Roundcube Fixes Zero Click XSS and SSRF Flaws in Mail Server

Roundcube Fixes Zero Click XSS and SSRF Flaws in Mail Server
CyberSIXT Evidence Panel Source marked as original reporting

ROUNDCUBE has issued a security update on 6 September 2026, addressing 12 vulnerabilities across the 1.6 LTS and 1.7 branches. The fixes span a zero-click stored cross-site scripting flaw, an SSRF bypass, and several email header injection issues. The zero-click stored XSS sits in the TNEF attachment handling, while another XSS flaw can be triggered by text/enriched content in the HTML editor.

In addition, attackers could forge mail headers—affecting the subject, recipient display name, and an identity’s organisation field—and a separate SSRF bypass abuse involved the CSS proxy using hex IPv6-mapped IPv4 addresses. Collectively, these flaws could enable spoofing and server-side request forgery.

The affected versions include all Roundcube 1.6.x and 1.7.x installations prior to 1.6.19 and 1.7.4. Nextcloud users should also check their bundled Roundcube package version. The authors credit external researchers, including Zach Hanley of Horizon3[.]ai, for the reports, but no CVE IDs have been assigned for this release, and there are no public PoC exploits or confirmed in-the-wild attacks cited.

The recommended mitigation is to upgrade immediately: move to 1.7.4 on the 1.7 branch or to 1.6.19 on the 1.6 LTS branch, with a reminder to back up data before upgrading and to consult the official Roundcube advisory for the complete fix list.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline