Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5049 articles · 189092 vulns · 37/41 feeds (7d)
← Back to list
4.7
CVE-2026-54432PATCHED
Roundcube · Webmail

CVE-2026-54432: Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS). The issue occurs becaus

Description

Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS) and other vulnerabilities. The XSS issue occurs because the attachment MIME type is not properly escaped on the attachment-validation warning page. Additional vulnerabilities include an infinite loop in TNEF (winmail.dat) decoder and vulnerabilities in the password plugin.

Affected Products

VendorProductVersions
RoundcubeWebmail1.6.0, 1.7.0

References

  • https://roundcube.net/news/2026/07/05/security-updates-1.6.17-and-1.7.2

Related News (4 articles)

Tier C
oss-security21d ago
CVE-2026-54432+more: Roundcube XSS/SSRF/etc prior to 1.6.17/1.7.2
→ No new info (linked only)
Tier C
VulDB29d ago
CVE-2026-54432 | Roundcube up to 1.6.16/1.7.1 Attachment-Validation Warning Type cross site scripting
→ No new info (linked only)
Tier B
BSI Advisories37d ago
[NEU] [mittel] Roundcube: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR37d ago
Multiples vulnérabilités dans Roundcube (06 juillet 2026)
→ No new info (linked only)
CVSS 3.14.7 MEDIUM
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
1.6.171.7.2
CWECWE-79
PublishedJul 14, 2026
Last enriched21d agov3
Tags
TNEFpassword-plugin
Trending Score4
Source articles4
Independent4
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-54433
CVE-2026-54433: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plai
Trending: 2
CRITICALCVE-2026-62644EXP
CVE-2026-62644: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to u
Trending: 1
HIGHCVE-2026-62642EXP
CVE-2026-62642: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which ma
Trending: 1
HIGHCVE-2026-62641
CVE-2026-62641: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a craft
Trending: 1
HIGHCVE-2026-62643EXP
CVE-2026-62643: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTM
Trending: 1

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 14, 2026
Discovered by ZDM
Jul 14, 2026
Updated: affectedVersions
Jul 14, 2026
Patch Available
Jul 15, 2026
Updated: description, tags
Jul 22, 2026

Version History

v3
Last enriched 21d ago
v3Tier C21d ago

Added details about TNEF decoder infinite loop and password plugin vulnerabilities, plus new tags for TNEF and password-plugin.

descriptiontags
via oss-security
v2Tier C29d ago

Updated affected versions to include 1.6.16 and 1.7.1, changed severity to HIGH, and noted that the vulnerability is actively exploited.

affectedVersions
via VulDB
v129d ago

Initial creation