blackorbird[verified]@blackorbirdDisclosure
The post discloses that Roundcube Webmail versions below 1.5.13/1.6.13 can force remote SVG feImage loads, bypassing the HTML sanitizer to track email opens, referencing CVE‑2026‑25916 and linking to further details.
Shivasurya[verified]@sshivasuryaActive Exploitation
The issue announces a new CVE in Roundcube, reports active exploitation via a malicious postmark MCP and MITM RCE through AMD’s AutoUpdate, and notes AI‑driven zero‑day discovery, underscoring recent real‑world attacks.
ThreatSynop[verified]@ThreatSynopDisclosure
The post discloses a new Roundcube vulnerability (CVE‑2026‑25916) that lets attackers use an invisible SVG to bypass image blocking, tracking email opens and leaking IP/browser details.
Open Source Security mailing list@oss_securityPatch
Roundcube issued security updates on Feb 8 to address two CVEs—one involving CSS injection and another involving an SVG-based image blocking bypass—without any indication of active exploitation or PoC.
ET Labs@ET_LabsGeneral
The snippet lists two CVEs with brief descriptive titles but provides no evidence of exploitation, patches, or PoCs.
iototsecnews@iototsecnewsDisclosure
The article reports a new Roundcube vulnerability (CVE‑2026‑25916) that lets attackers track email opens by exploiting a sanitization flaw involving SVG <feImage> tags. No evidence of exploitation, patch details, or PoC is provided.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The text lists CVE-2026-25916 with a brief description of an SVG feImage remote image bypass in Roundcube Webmail, but provides no further details.
CVE@CVEnewDisclosure
CVE-2026-25916 impacts Roundcube Webmail versions prior to 1.5.13 and 1.6.13; the "Block remote images" setting does not block SVG feImage, exposing a potential vector for malicious content.