
CVE-2026-35540 An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or I… https://www.cve.org/CVERecord?id=CVE-2026-35540
Post summary
A new vulnerability (CVE-2026-35540) affecting Roundcube Webmail 1.6.0‑1.6.13 involves insufficient CSS sanitization that could lead to SSRF attacks; no PoC, exploit, or patch details are provided.
