ROUNDCUBE released two critical security updates (versions 1.6.18 and 1.7.3), fixing eleven vulnerabilities including a severe Remote Code Execution (RCE) flaw in a spam-training plugin and Security Server Request Forgery (SSRF) issues. These vulnerabilities can allow attackers to target internal services, making Roundcube a soft target for exploitation. The fixes are essential for users of versions 1.6.x before 1.6.18 and 1.7.x before 1.7.3, with no active exploitation reported yet. Admins are urged to update their installations immediately to avoid potential takeovers.
Roundcube fixes critical RCE and SSRF flaws in new update
CyberSIXT Evidence Panel
Primary Source
roundcube.net
Article by CyberSIXT