Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5049 articles · 189092 vulns · 37/41 feeds (7d)
← Back to list
4.3
CVE-2026-62641PATCHED
roundcube · webmail

CVE-2026-62641: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a craft

Description

A vulnerability classified as problematic was found in Roundcube up to 1.6.16/1.7.1. Affected by this vulnerability is an unknown functionality of the component TNEF decoder. The manipulation results in cross site scripting. The attack may be performed from remote.

Affected Products

VendorProductVersions
roundcubewebmail1.6.0, 1.7.0, 1.6.16, 1.7.1

References

  • https://roundcube.net/news/2026/07/05/security-updates-1.6.17-and-1.7.2
  • https://github.com/roundcube/roundcubemail/releases/tag/1.7.2
  • https://github.com/roundcube/roundcubemail/commit/6d1004fd3764a9606c53130b322c0f295c38be64
  • https://github.com/roundcube/roundcubemail/releases/tag/1.6.17
  • https://github.com/roundcube/roundcubemail/commit/bf253c72d4293c93fda511b8464fe9cb34b522c1

Related News (1 articles)

Tier C
VulDB29d ago
CVE-2026-62641 | Roundcube up to 1.6.16/1.7.1 TNEF decoder cross site scripting
→ No new info (linked only)
CVSS 3.14.3 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
CISA KEV❌ No
Actively exploited❌ No
Patch available
1.6.171.7.2
CWECWE-770
PublishedJul 14, 2026
Last enriched29d agov2
Trending Score1
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-54432
CVE-2026-54432: Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS). The issue occurs becaus
Trending: 4
HIGHCVE-2026-54433
CVE-2026-54433: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plai
Trending: 2
CRITICALCVE-2026-62644EXP
CVE-2026-62644: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to u
Trending: 1
HIGHCVE-2026-62642EXP
CVE-2026-62642: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which ma
Trending: 1
HIGHCVE-2026-62643EXP
CVE-2026-62643: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTM
Trending: 1

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 14, 2026
Discovered by ZDM
Jul 14, 2026
Patch Available
Jul 14, 2026
Updated: description, affectedVersions, severity
Jul 14, 2026

Version History

v2
Last enriched 29d ago
v2Tier C29d ago

Updated description with new details, changed severity to HIGH, and modified affected versions to include 1.6.16 and 1.7.1.

descriptionaffectedVersionsseverity
via VulDB
v129d ago

Initial creation