Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5049 articles · 189092 vulns · 37/41 feeds (7d)
← Back to list
4.3
CVE-2026-62642EXPLOITEDPATCHED
roundcube · webmail

CVE-2026-62642: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which ma

Description

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which may lead to denial of service upon opening an email with a TNEF attachment.

Affected Products

VendorProductVersions
roundcubewebmail1.6.0, 1.7.0, 1.6.16, 1.7.1

References

  • https://roundcube.net/news/2026/07/05/security-updates-1.6.17-and-1.7.2
  • https://github.com/roundcube/roundcubemail/releases/tag/1.7.2
  • https://github.com/roundcube/roundcubemail/commit/877269c79359d959a94f13c9070cab0f3389c193
  • https://github.com/roundcube/roundcubemail/commit/fb952956c6eaf29e963f1a718d028d66e7957ce0
  • https://github.com/roundcube/roundcubemail/releases/tag/1.6.17
  • https://github.com/roundcube/roundcubemail/commit/a007321346380136b3de2bd75b486b04f63c0d38
  • https://github.com/roundcube/roundcubemail/commit/132ac8dd5a55c8466be12de1daf84355697ffa89

Related News (1 articles)

Tier C
VulDB29d ago
CVE-2026-62642 | Roundcube Webmail up to 1.6.16/1.7.1 TNEF Decoder infinite loop
→ No new info (linked only)
CVSS 3.14.3 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
1.6.171.7.2
CWECWE-835
PublishedJul 14, 2026
Last enriched29d agov2
Trending Score1
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-54432
CVE-2026-54432: Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS). The issue occurs becaus
Trending: 4
HIGHCVE-2026-54433
CVE-2026-54433: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plai
Trending: 2
CRITICALCVE-2026-62644EXP
CVE-2026-62644: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to u
Trending: 1
HIGHCVE-2026-62641
CVE-2026-62641: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a craft
Trending: 1
HIGHCVE-2026-62643EXP
CVE-2026-62643: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTM
Trending: 1

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 14, 2026
Actively Exploited
Jul 14, 2026
Patch Available
Jul 14, 2026
Discovered by ZDM
Jul 14, 2026
Updated: affectedVersions, severity, activelyExploited
Jul 14, 2026

Version History

v2
Last enriched 29d ago
v2Tier C29d ago

Updated affected versions to include 1.6.16 and 1.7.1, changed severity to HIGH, and marked the vulnerability as actively exploited.

affectedVersionsseverityactivelyExploited
via VulDB
v129d ago

Initial creation