
CVE-2026-35544 An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to a fi… https://www.cve.org/CVERecord?id=CVE-2026-35544
Post summary
A new CVE (CVE‑2026‑35544) affecting Roundcube Webmail before versions 1.5.14 and 1.6.14 is disclosed, highlighting insufficient CSS sanitization in HTML email messages.
