Debian Roundcube Vulnerabilities Lead to CSS Injection and Information Disclosure

Debian Roundcube Vulnerabilities Lead to CSS Injection and Information Disclosure

First seen 17 Feb 2026, 20:11 UTC Linuxsecurity 32.3

Article Content

Browse articles
ThreatCluster

Debian has released updates for Roundcube to address two critical vulnerabilities affecting email security. CVE-2026-25916 allows attackers to bypass image blocking, while CVE-2026-26079 enables CSS injection in emails. Users of Debian 11, oldstable (bookworm), and stable (trixie) distributions are advised to upgrade their Roundcube packages to mitigate these risks.

Timeline

2026-02-09
CVE-2026-25916 published
2026-02-11
CVE-2026-26079 published
2026-02-17
Debian releases updates for affected Roundcube versions