CVE-2026-54432Patch

LOWCVSS 4.7 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS). The issue occurs because the attachment MIME type is not properly escaped on the attachment-validation warning page.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-07-10); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-07-10: 3Mentions · 2026-07-17: 1Patch / Workaround · 2026-07-10: 2Patch / Workaround · 2026-07-17: 1Technical Details · 2026-07-10: 2Technical Details · 2026-07-17: 107-1007-17
Signal classification2 categories
Patch
375.0%
Disclosure
125.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-07-103
Disclosure1Patch2
2026-07-171
Patch1
Full discourse4 posts
  • Directoratul Național de Securitate Cibernetică@DNSC_RO
    Patch

    🚨 ALERTĂ - Vulnerabilități critice în Roundcube Webmail ⚠️ Roundcube a publicat actualizările de securitate 1.6.17 și 1.7.2, care remediază vulnerabilități identificate în aplicația Roundcube Webmail, CVE-2026-54432 și CVE-2026-54433. 👉 https://www.dnsc.ro/citeste/alerta-vulnerabilitati-critice-in-roundcube-webmail #DNSC https://t.co/wMwMEsMee0

    Post summary

    Roundcube released updates 1.6.17 and 1.7.2 to patch CVE-2026-54432 and CVE-2026-54433; no exploit or PoC details are given.

    02031275
    4.7K followersView on X
  • Clone Systems@CloneSystemsInc
    Patch

    Roundcube has released security updates 1.7.2 and 1.6.17 to address multiple vulnerabilities, including zero click stored cross site scripting, SSRF bypass issues, password plugin flaws, and denial of service risks. The most concerning issue is CVE-2026-54433, a zero click stored XSS vulnerability in plain text rendering. That means a malicious email could potentially trigger script execution without the user needing to click a link or open an attachment. The update also fixes CVE-2026-54432, a stored XSS issue involving attachment MIME type handling, along with DoS risks tied to crafted winmail.dat files. For organizations using Roundcube Webmail, this is a clear patch now moment. Webmail is a common entry point for phishing, credential theft, and account takeover attempts, and zero click exposure raises the urgency. Admins should upgrade to Roundcube 1.7.2 or 1.6.17 immediately, review exposed webmail instances, and monitor for suspicious email behavior or unusual account activity. When email can become the trigger, patching cannot wait for someone to click. #Roundcube #WebmailSecurity #CVE202654433 #CVE202654432 #ZeroClick #CrossSiteScripting #VulnerabilityManagement #PatchManagement #EmailSecurity #CyberRisk

    Post summary

    Roundcube releases updates 1.7.2/1.6.17 to fix CVE‑2026‑54433 and CVE‑2026‑54432, highlighting zero‑click stored XSS and DoS issues, urging organizations to patch promptly.

    0001098
    259 followersView on X
  • iototsecnews@iototsecnews
    Patch

    Roundcube の脆弱性 CVE-2026-54433/54432 などが FIX:深刻な蓄積型 XSS 攻撃の恐れ https://iototsecnews.jp/2026/07/10/roundcube-webmail-security-update-patches-critical-zero-click-xss-and-ssrf-bypass-flaws/ 日常のコミュニケーションを支える Roundcube において、受信データの処理部分に予期せぬ不備が紛れ込んでいました。それにより、この Web メール製品の環境において、メール本文や添付データの解析処理に関する問題が確認されました。今回の発表によると、 CVE-2026-54433/CVE-2026-54432 などを含む複数の欠陥により、メッセージを閲覧しただけで不正なプログラムが動き出し、大切なインタラクションの内容を盗み見られてしまうといった影響が生じえます。通信環境の安全を確保するために、提供されている最新のバージョン 1.7.2 へのアップデートを速やかに適用し、全体の防御力を高める必要があります。 #CVE202654432 #CVE202654433 #Roundcube #Vulnerability

    Post summary

    The article announces critical XSS and SSRF bypass vulnerabilities (CVE‑2026‑54433/54432) in Roundcube and recommends applying the 1.7.2 security patch to remediate the issue.

    00000101
    501 followersView on X
  • Maxprotect@Maxprotectsoc
    Disclosure

    @The_Cyber_News The most dangerous attack surface is often the validation logic itself. By weaponizing the MIME type warning page, CVE-2026-54432 grants an attacker full, silent JS execution the moment the email is viewed. Traditional email gateway filters will completely miss this payload.

    Post summary

    The post discloses that CVE‑2026‑54432 enables silent JavaScript execution when an email is examined, exploiting a MIME type warning page, but lacks PoC, exploit code, patch, or evidence of ongoing attacks.

    0000050
    33 followersView on X

Explore more