CVE-2026-35537Disclosure(roundcube / webmail)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbitrary file write operations by unauthenticated attackers via crafted session data.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • webmail

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
webmail

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-03: 2Technical Details · 2026-04-03: 104-03
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-35537 An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbitrary file write o… https://www.cve.org/CVERecord?id=CVE-2026-35537

    Post summary

    The entry flags an unsafe deserialization bug in Roundcube Webmail that can lead to arbitrary file writes before versions 1.5.14 and 1.6.14, but offers no additional details on exploitation or remediation.

    00000124
    56.9K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-35537 📊 Severity: 3.7 🚨 Risk Level: Low 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-35537 #CVE-2026-35537 #CVE #Low #CyberSecurity #InfoSec https://t.co/keO2XETWOj

    Post summary

    A new low‑severity CVE (CVE‑2026‑35537) was announced, providing only basic impact information and directing readers to the NVD entry for more detail.

    0000041
    122 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Approundcubewebmail---

Explore more