Clone Systems[verified]@CloneSystemsIncPatch
Roundcube has released version 1.7.2/1.6.17 patches addressing critical XSS and DoS issues, notably CVE-2026-54433. Organizations are urged to upgrade immediately to mitigate the zero‑click vulnerability.
webhosting.today[verified]@WebhostingTodayPatch
Roundcube and cPanel quickly addressed a zero-click XSS vulnerability (CVE‑2026‑54433) with official patches, and no exploitation has been reported.
Daily CyberSecurity@Daily_CyberSecPatch
The post announces a zero‑click XSS vulnerability (CVE‑2026‑54433) in Roundcube, includes technical details, and urges users to update to version 1.7.2.
Directoratul Național de Securitate Cibernetică@DNSC_ROPatch
Roundcube released security updates 1.6.17 and 1.7.2 to address CVE-2026-54432 and CVE-2026-54433; the post contains no PoC, exploit code, or evidence of active exploitation.
takenaka hiroya@Joe_Biden_jaPatch
CVE‑2026‑54433 is a stored XSS vulnerability in Roundcube Webmail that can be triggered with a zero‑click by opening or previewing a crafted email. It is patched in versions 1.6.17 and 1.7.2, with Debian having applied the fixes.
CERT-PY@CERTpyGeneral
A brief notice alerts to a CVE‑2026‑54433 vulnerability affecting Roundcube products, with further information directed to a provided link.
iototsecnews@iototsecnewsPatch
The article reports critical XSS and SSRF bypass vulnerabilities in Roundcube (CVE‑2026‑54432/33) and urges users to update to version 1.7.2.