
CVE-2026-35537 An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbitrary file write o… https://www.cve.org/CVERecord?id=CVE-2026-35537
Post summary
The entry flags an unsafe deserialization bug in Roundcube Webmail that can lead to arbitrary file writes before versions 1.5.14 and 1.6.14, but offers no additional details on exploitation or remediation.

