CVE-2026-25916Disclosure

MEDIUMCVSS 4.3 · MEDIUM

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when "Block remote images" is used, does not block SVG feImage.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-420

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 5 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 8 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 4 mentions (2026-02-09); latest day: 1
  • 8 total mentions across 5 days

Deep dive

Activity timeline8 mentions / 5d
01234Mentions · 2026-02-09: 4Mentions · 2026-02-10: 1Mentions · 2026-02-11: 1Mentions · 2026-02-17: 1Mentions · 2026-02-23: 1PoC Mentioned / Linked · 2026-02-09: 1Active Exploitation · 2026-02-11: 1Patch / Workaround · 2026-02-23: 1Technical Details · 2026-02-09: 4Technical Details · 2026-02-10: 1Technical Details · 2026-02-11: 1Technical Details · 2026-02-17: 1Technical Details · 2026-02-23: 102-0902-1002-1102-1702-23
Signal classification4 categories
Disclosure
562.5%
General
112.5%
Active Exploitation
112.5%
Patch
112.5%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-094
Disclosure4
2026-02-101
General1
2026-02-111
Active Exploitation1
2026-02-171
Disclosure1
2026-02-231
Patch1
Full discourse8 posts
  • blackorbird@blackorbird
    Disclosure

    Roundcube Webmail <1.5.13 / <1.6.13 allows attackers to force remote image loads via SVG feImage Roundcube's HTML sanitizer doesn't treat SVG feImage href as an image source. Attackers can bypass remote image blocking to track email opens. (CVE-2026-25916) https://nullcathedral.com/posts/2026-02-08-roundcube-svg-feimage-remote-image-bypass/

    Post summary

    The post discloses that Roundcube Webmail versions below 1.5.13/1.6.13 can force remote SVG feImage loads, bypassing the HTML sanitizer to track email opens, referencing CVE‑2026‑25916 and linking to further details.

    040731.7K
    39.9K followersView on X
  • Open Source Security mailing list@oss_security
    Patch

    CVE-2026-26079,CVE-2026-25916: Roundcube vulns https://www.openwall.com/lists/oss-security/2026/02/23/1 Roundcube PHP-based webmail frontend released security updates on Feb 8 * Fix CSS injection vulnerability reported by CERT Polska * Fix remote image blocking bypass via SVG content reported by nullcathedral

    Post summary

    Roundcube issued security updates on Feb 8 to address two CVEs—one involving CSS injection and another involving an SVG-based image blocking bypass—without any indication of active exploitation or PoC.

    01041484
    4.4K followersView on X
  • Shivasurya@sshivasurya
    Active Exploitation

    This week in appsec: Issue #19 > Roundcube forgot SVG image bypasses remote image blocking and tracks email opens (CVE-2026-25916) > First malicious MCP in the wild: postmark-mcp v1.0.16 silently BCCs attackers on every AI-sent email > AMD Windows AutoUpdate downloads executables over plain HTTP with zero signature checks for trivial MITM RCE > Claude Opus 4.6 autonomously discovered hundreds of real 0-days in heavily fuzzed open source projects > Autonomous AI pentesters arrive: CyberStrikeAI, Shannon, and VulnLLM-R-7B turn "scan this app" into natural language https://appsecweekly.net/p/issue-19-appsec-weekly-feb-9-2026

    Post summary

    The issue announces a new CVE in Roundcube, reports active exploitation via a malicious postmark MCP and MITM RCE through AMD’s AutoUpdate, and notes AI‑driven zero‑day discovery, underscoring recent real‑world attacks.

    01021147
    695 followersView on X
  • ET Labs@ET_Labs
    General

    19 new OPEN, 32 new PRO (19 + 13) Quest KACE Desktop Insecure Named Pipe (CVE-2025-67813), Roundcube Webmail SVG felImage Remote Image Bypass (CVE-2026-25916) , ZPHP, LandUpdate808, Evil Keitaro, TA569 and more. https://community.emergingthreats.net/t/ruleset-update-summary-2026-02-10-v11122/3193

    Post summary

    The snippet lists two CVEs with brief descriptive titles but provides no evidence of exploitation, patches, or PoCs.

    01010255
    5.7K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Roundcube の脆弱性 CVE-2026-25916 が FIX:サニタイザーの不備によるプライバシー侵害 https://iototsecnews.jp/2026/02/09/roundcube-webmail-vulnerability-let-attackers-track-email-opens/ オープンソースの Web メールソフト Roundcube に、ユーザーのプライバシー設定をすり抜けてメールの開封を追跡できてしまう脆弱性が発見されました。この問題の原因は、メール内の危険な要素を取り除く HTMLサニタイザーという機能の欠陥により、特定の画像の読み込みを阻止できなかったことにあります。Roundcubeには外部画像の読み込みをブロックする設定がありますが、SVG 形式の画像内で使われる <feImage> という特殊なタグが画像として認識されていませんでした。そのため、このタグに含まれる URL が、クリックが必要な通常のリンクとして誤って処理され、メールを開いた瞬間に、外部サーバへの通信が自動的に発生するという状態になっています。ご利用のチームは、ご注意ください。 #CVE202625916 #Privacy #Roundcube #Vulnerability

    Post summary

    The article reports a new Roundcube vulnerability (CVE‑2026‑25916) that lets attackers track email opens by exploiting a sanitization flaw involving SVG <feImage> tags. No evidence of exploitation, patch details, or PoC is provided.

    01000134
    484 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25916 SVG feImage Remote Image Bypass Vulnerability in Roundcube Webmail https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25916

    Post summary

    The text lists CVE-2026-25916 with a brief description of an SVG feImage remote image bypass in Roundcube Webmail, but provides no further details.

    0000061
    4.0K followersView on X
  • ThreatSynop@ThreatSynop
    Disclosure

    🚨 Roundcube Bug Lets Attackers Track “Email Opens” Even When Remote Images Are Blocked (CVE-2026-25916) A flaw in Roundcube’s HTML/SVG sanitization lets attackers embed an invisible SVG ` ` that bypasses “Block remote images,” causing the client to fetch a remote resource and leak open confirmation plus IP/browser details. This matters because it enables stealthy tracking and profiling of victims (and potential targeting) simply by viewing an email on vulnerable Roundcube versions (<1.5.13 / <1.6.13). 🎯 Target: Global/Webmail (Roundcube users) #️⃣ Category: #Vulnerability 🔗 URL: https://cyberpress.org/roundcube-webmail-vulnerability-lets-attackers-track-email-opens/

    Post summary

    The post discloses a new Roundcube vulnerability (CVE‑2026‑25916) that lets attackers use an invisible SVG to bypass image blocking, tracking email opens and leaking IP/browser details.

    0000055
    191 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25916 Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when "Block remote images" is used, does not block SVG feImage. https://www.cve.org/CVERecord?id=CVE-2026-25916

    Post summary

    CVE-2026-25916 impacts Roundcube Webmail versions prior to 1.5.13 and 1.6.13; the "Block remote images" setting does not block SVG feImage, exposing a potential vector for malicious content.

    00000280
    56.5K followersView on X

Explore more