Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2092 articles · 104287 vulns · 38/41 feeds (7d)
← Back to list
5.3
CVE-2026-35543PATCHED
roundcube · webmail

CVE-2026-35543: An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed

Description

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via SVG content (with animate attributes) in an e-mail message. This may lead to information disclosure or access-control bypass.

Affected Products

VendorProductVersions
roundcubewebmailcomposer/roundcube/roundcubemail: >= 1.7-beta, < 1.7-rc5

References

  • https://roundcube.net/news/2026/03/18/security-updates-1.7-rc5-1.6.14-1.5.14
  • https://github.com/roundcube/roundcubemail/releases/tag/1.7-rc5
  • https://github.com/roundcube/roundcubemail/commit/82ab5eca7b332fce7a174b2b987f0957a66377cd
  • https://github.com/roundcube/roundcubemail/releases/tag/1.6.14
  • https://github.com/roundcube/roundcubemail/commit/39471343ee081ce1d31696c456a2c163462daae3
  • https://github.com/roundcube/roundcubemail/releases/tag/1.5.14
  • https://github.com/roundcube/roundcubemail/commit/1a63e01542bff42aaa71c00c4c279a09ef31f20c

Related News (1 articles)

Tier C
VulDB2d ago
CVE-2026-35543 | Roundcube Webmail up to 1.5.13/1.6.13 SVG Content resource transfer
→ No new info (linked only)
CVSS 3.15.3 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
roundcube/roundcubemail@1.7-rc5
CWECWE-669
PublishedApr 3, 2026
Last enriched2d agov2
Tags
problematic
Trending Score23
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-35544EXP
CVE-2026-35544: An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitiz
Trending: 46
MEDIUMCVE-2026-35542EXP
CVE-2026-35542: An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed
Trending: 35
MEDIUMCVE-2026-35540EXP
CVE-2026-35540: An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization
Trending: 28
MEDIUMCVE-2026-35545
CVE-2026-35545: An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed
Trending: 23
MEDIUMCVE-2026-35541
CVE-2026-35541: An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plu
Trending: 15

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Apr 3, 2026
Discovered by ZDM
Apr 3, 2026
Updated: affectedVersions, severity, tags
Apr 3, 2026
Patch Available
Apr 3, 2026

Version History

v2
Last enriched 2d ago
v2Tier C2d ago

Updated affected versions to include 1.5.13 and 1.6.13, changed severity to HIGH, and noted that no exploit is available.

affectedVersionsseveritytags
via VulDB
v12d ago

Initial creation