Skip to content
Roundcube Webmail Vulnerability Allows Email Open Tracking

Roundcube Webmail Vulnerability Allows Email Open Tracking

First seen 10 Feb 2026, 01:07 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 24, 2026 at 10:43 UTC

A critical Cross-Site Scripting (XSS) vulnerability has been identified in Roundcube Webmail, enabling attackers to track email opens by loading remote images. This flaw affects users who have set their preferences to block remote images, compromising their privacy. Security updates have been released to address this issue.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 171d ago How this analysis works

Timeline

2026-02-09
Vulnerability disclosed by NULL CATHEDRAL
2026-02-09
Roundcube released critical security updates

More articles in this cluster (23)