Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4989 articles · 189008 vulns · 37/41 feeds (7d)
← Back to list
7.2
CVE-2026-62643EXPLOITEDPATCHED
roundcube · webmail

CVE-2026-62643: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTM

Description

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. NOTE: this issue exists because of insufficient fixes for CVE-2026-35540 and CVE-2026-48843.

Affected Products

VendorProductVersions
roundcubewebmail1.6.0, 1.7.0, 1.6.16, 1.7.1

References

  • https://roundcube.net/news/2026/07/05/security-updates-1.6.17-and-1.7.2
  • https://github.com/roundcube/roundcubemail/releases/tag/1.7.2
  • https://github.com/roundcube/roundcubemail/commit/6d69e094d55d3a9a84dfb36edf6ca985311f0c1c
  • https://github.com/roundcube/roundcubemail/releases/tag/1.6.17
  • https://github.com/roundcube/roundcubemail/commit/294c7da6e7284166f040cef8607b677d459e0786

Related News (1 articles)

Tier C
VulDB29d ago
CVE-2026-62643 | Roundcube Webmail up to 1.6.16/1.7.1 CSS server-side request forgery
→ No new info (linked only)
CVSS 3.17.2 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
1.6.171.7.2
CWECWE-918
PublishedJul 14, 2026
Last enriched29d agov2
Trending Score1
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-54432
CVE-2026-54432: Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS). The issue occurs becaus
Trending: 4
HIGHCVE-2026-54433
CVE-2026-54433: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plai
Trending: 3
CRITICALCVE-2026-62644EXP
CVE-2026-62644: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to u
Trending: 1
HIGHCVE-2026-62642EXP
CVE-2026-62642: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which ma
Trending: 1
HIGHCVE-2026-62641
CVE-2026-62641: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a craft
Trending: 1

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 14, 2026
Actively Exploited
Jul 14, 2026
Patch Available
Jul 14, 2026
Discovered by ZDM
Jul 14, 2026
Updated: affectedVersions, activelyExploited
Jul 14, 2026

Version History

v2
Last enriched 29d ago
v2Tier C29d ago

Updated affected versions to include 1.6.16 and 1.7.1, and marked the vulnerability as actively exploited.

affectedVersionsactivelyExploited
via VulDB
v129d ago

Initial creation