
CVE-2026-35539 An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment sanitization in preview mode. A victim must … https://www.cve.org/CVERecord?id=CVE-2026-35539
Post summary
A new XSS vulnerability in Roundcube Webmail before 1.5.14/1.6.14 has been disclosed, with insufficient HTML attachment sanitization identified as the flaw.
