Itsecuritynews.Info Roundcube Webmail Vulnerability Allows Email Open Tracking
Article Content
Browse articles
A critical Cross-Site Scripting (XSS) vulnerability has been identified in Roundcube Webmail, enabling attackers to track email opens by loading remote images. This flaw affects users who have set their preferences to block remote images, compromising their privacy. Security updates have been released to address this issue.
Ask AI about this cluster
Answers cite the sources they use
Updated 171d ago How this analysis works
Timeline
2026-02-09
Vulnerability disclosed by NULL CATHEDRAL
2026-02-09
Roundcube released critical security updates
More articles in this cluster (23)
Continue Reading
Critical Stored XSS Vulnerabilities Found in SiYuan Versions Before 3.7.4 Two critical vulnerabilities, CVE-2026-73050 and CVE-2026-73052, have been identified in SiYuan versions prior to 3.7.4. CVE-2026-73050 allows attackers to exploit stored cross-site scripting (XSS) via unescaped color fields in select options, executing arbitrary JavaScript in victim browsers. CVE-2026-73052 enables…