Skip to content
Roundcube Webmail Patches Critical Zero-Click XSS Vulnerabilities

Roundcube Webmail Patches Critical Zero-Click XSS Vulnerabilities

First seen 10 Jul 2026, 04:56 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 1, 2026 at 14:16 UTC
  • •Roundcube version 1.7.2 addresses critical zero-click XSS vulnerabilities.
  • •The vulnerabilities were reported by researchers from Samsung R&D Institute Ukraine.
  • •Immediate update to the latest version is strongly recommended for all users.

Roundcube has released version 1.7.2 to address multiple high-impact vulnerabilities, including a critical zero-click stored cross-site scripting (XSS) flaw and a server-side request forgery (SSRF) bypass. The vulnerabilities were reported by researchers from Samsung R&D Institute Ukraine and others. The zero-click XSS vulnerability allows attackers to execute scripts without user interaction, posing a significant risk to users of Roundcube Webmail. All production deployments are strongly advised to update to the latest version immediately. The update aims to mitigate the risks associated with these vulnerabilities, which could potentially lead to unauthorized access or data breaches. The vulnerabilities were disclosed responsibly, and the update is critical for maintaining security in affected systems.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-07-09
Roundcube version 1.7 released
Version 1.7 was released to patch six security vulnerabilities, including critical XSS flaws.
Cybersecuritynews
2026-07-10
Roundcube version 1.7.2 released
Version 1.7.2 was released to address multiple high-impact vulnerabilities, including a zero-click XSS flaw.
Gbhackers

More articles in this cluster (2)

Common questions

Which versions are affected?
Versions prior to 1.7.2 of Roundcube Webmail are affected by the vulnerabilities.
Is there active exploitation of these vulnerabilities?
No confirmed active exploitation has been reported as of now.
What should I do to secure my system?
Update to Roundcube version 1.7.2 immediately to mitigate the vulnerabilities.