Roundcube Webmail Vulnerability Allows Email Open Tracking

Roundcube Webmail Vulnerability Allows Email Open Tracking

First seen 10 Feb 2026, 01:07 UTC CybersecuritynewsItsecuritynews.InfoSecurityaffairs.CoHeise.DeGbhackers+6 86% similarity 25.9

Article Content

Browse articles
ThreatCluster

A critical Cross-Site Scripting (XSS) vulnerability has been identified in Roundcube Webmail, enabling attackers to track email opens by loading remote images. This flaw affects users who have set their preferences to block remote images, compromising their privacy. Security updates have been released to address this issue.

ThreatCluster AI How this analysis works

Timeline

2026-02-09
Vulnerability disclosed by NULL CATHEDRAL
2026-02-09
Roundcube released critical security updates

Community

Browse all →

Tracked Entities in This Story