CVE-2026-54433Patch(roundcube / webmail)

LOWCVSS 10.0 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch roundcube webmail systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the victim's authenticated session simply by opening or previewing the message (zero-click).

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • webmail

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 5 signals
  • General: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-07-10); latest day: 1
  • 7 total mentions across 5 days

Affected systems

Vendors
Products
webmail

Deep dive

Activity timeline7 mentions / 5d
01122Mentions · 2026-07-09: 1Mentions · 2026-07-10: 2Mentions · 2026-07-15: 1Mentions · 2026-07-17: 2Mentions · 2026-08-10: 1PoC Mentioned / Linked · 2026-07-09: 1Patch / Workaround · 2026-07-09: 1Patch / Workaround · 2026-07-10: 2Patch / Workaround · 2026-07-15: 1Patch / Workaround · 2026-07-17: 1Patch / Workaround · 2026-08-10: 1Technical Details · 2026-07-09: 1Technical Details · 2026-07-10: 1Technical Details · 2026-07-15: 1Technical Details · 2026-07-17: 1Technical Details · 2026-08-10: 107-0907-1007-1507-1708-10
Signal classification2 categories
Patch
685.7%
General
114.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-07-091
Patch1
2026-07-102
Patch2
2026-07-151
Patch1
2026-07-172
General1Patch1
2026-08-101
Patch1
Full discourse7 posts
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    A Roundcube zero-click XSS, CVE-2026-54433, lets an email run script with no click. Roundcube 1.7.2 also fixes a second stored XSS. Update now. #Roundcube #XSS #ZeroClick #Webmail #StoredXSS #CyberSecurity #Vulnerability #InfoSec http://securityonline.info/roundcube-zero-click-xss-cve-2026-54433/

    Post summary

    The post announces a zero‑click XSS vulnerability (CVE‑2026‑54433) in Roundcube, includes technical details, and urges users to update to version 1.7.2.

    0322051.8K
    12.9K followersView on X
  • Directoratul Național de Securitate Cibernetică@DNSC_RO
    Patch

    🚨 ALERTĂ - Vulnerabilități critice în Roundcube Webmail ⚠️ Roundcube a publicat actualizările de securitate 1.6.17 și 1.7.2, care remediază vulnerabilități identificate în aplicația Roundcube Webmail, CVE-2026-54432 și CVE-2026-54433. 👉 https://www.dnsc.ro/citeste/alerta-vulnerabilitati-critice-in-roundcube-webmail #DNSC https://t.co/wMwMEsMee0

    Post summary

    Roundcube released security updates 1.6.17 and 1.7.2 to address CVE-2026-54432 and CVE-2026-54433; the post contains no PoC, exploit code, or evidence of active exploitation.

    02031275
    4.7K followersView on X
  • takenaka hiroya@Joe_Biden_ja
    Patch

    Roundcube Webmail のプレーンテキスト描画に格納型XSS。細工したメールを開く、あるいはプレビューするだけで実行されるゼロクリックです。NVD一次スコアはCVSS 10.0。修正版は1.6.17と1.7.2で、Debianは全スイート修正済み。自己ホストしている… https://cve.autoarticles.net/cve/CVE-2026-54433

    Post summary

    CVE‑2026‑54433 is a stored XSS vulnerability in Roundcube Webmail that can be triggered with a zero‑click by opening or previewing a crafted email. It is patched in versions 1.6.17 and 1.7.2, with Debian having applied the fixes.

    00010140
    562 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidad en productos Roundcube ❗ CVE-2026-54433 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-roundcube/ https://t.co/sQG9TmziB0

    Post summary

    A brief notice alerts to a CVE‑2026‑54433 vulnerability affecting Roundcube products, with further information directed to a provided link.

    00001278
    6.7K followersView on X
  • Clone Systems@CloneSystemsInc
    Patch

    Roundcube has released security updates 1.7.2 and 1.6.17 to address multiple vulnerabilities, including zero click stored cross site scripting, SSRF bypass issues, password plugin flaws, and denial of service risks. The most concerning issue is CVE-2026-54433, a zero click stored XSS vulnerability in plain text rendering. That means a malicious email could potentially trigger script execution without the user needing to click a link or open an attachment. The update also fixes CVE-2026-54432, a stored XSS issue involving attachment MIME type handling, along with DoS risks tied to crafted winmail.dat files. For organizations using Roundcube Webmail, this is a clear patch now moment. Webmail is a common entry point for phishing, credential theft, and account takeover attempts, and zero click exposure raises the urgency. Admins should upgrade to Roundcube 1.7.2 or 1.6.17 immediately, review exposed webmail instances, and monitor for suspicious email behavior or unusual account activity. When email can become the trigger, patching cannot wait for someone to click. #Roundcube #WebmailSecurity #CVE202654433 #CVE202654432 #ZeroClick #CrossSiteScripting #VulnerabilityManagement #PatchManagement #EmailSecurity #CyberRisk

    Post summary

    Roundcube has released version 1.7.2/1.6.17 patches addressing critical XSS and DoS issues, notably CVE-2026-54433. Organizations are urged to upgrade immediately to mitigate the zero‑click vulnerability.

    0001098
    259 followersView on X
  • iototsecnews@iototsecnews
    Patch

    Roundcube の脆弱性 CVE-2026-54433/54432 などが FIX:深刻な蓄積型 XSS 攻撃の恐れ https://iototsecnews.jp/2026/07/10/roundcube-webmail-security-update-patches-critical-zero-click-xss-and-ssrf-bypass-flaws/ 日常のコミュニケーションを支える Roundcube において、受信データの処理部分に予期せぬ不備が紛れ込んでいました。それにより、この Web メール製品の環境において、メール本文や添付データの解析処理に関する問題が確認されました。今回の発表によると、 CVE-2026-54433/CVE-2026-54432 などを含む複数の欠陥により、メッセージを閲覧しただけで不正なプログラムが動き出し、大切なインタラクションの内容を盗み見られてしまうといった影響が生じえます。通信環境の安全を確保するために、提供されている最新のバージョン 1.7.2 へのアップデートを速やかに適用し、全体の防御力を高める必要があります。 #CVE202654432 #CVE202654433 #Roundcube #Vulnerability

    Post summary

    The article reports critical XSS and SSRF bypass vulnerabilities in Roundcube (CVE‑2026‑54432/33) and urges users to update to version 1.7.2.

    00000101
    501 followersView on X
  • webhosting.today@WebhostingToday
    Patch

    Roundcube patched a zero-click XSS in its webmail (CVE-2026-54433, CVSS 7.2) on July 5. @cPanel shipped the fix nine days later in 134.0.45. No sign of exploitation, so patch on schedule, not in a panic. cPanel: 134.0.45+. Standalone: 1.6.17 / 1.7.2. 👇 https://webhosting.today/2026/07/15/roundcubes-zero-click-webmail-xss-and-how-fast-it-reached-cpanel/ #cPanel #Roundcube #Cybersecurity #WebHosting

    Post summary

    Roundcube and cPanel quickly addressed a zero-click XSS vulnerability (CVE‑2026‑54433) with official patches, and no exploitation has been reported.

    0000060
    33 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Approundcubewebmail---

Explore more