CVE-2026-74997Patch(roundcube / webmail)

LOWCVSS 8.8 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch roundcube webmail systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder replacement values. This issue only affects Roundcube instances using the markasjunk plugin with its cmd_learn driver.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • webmail

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
webmail

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-18: 3Patch / Workaround · 2026-08-18: 2Technical Details · 2026-08-18: 208-18
Signal classification2 categories
Patch
266.7%
General
133.3%
Referenced assets2 URLs
Full discourse3 posts
  • iSECTECH@isectech_
    General

    Good vulnerability triage asks “Are we exposed?” before “What is the CVSS?” For Roundcube CVE-2026-74997, inventory the plugin driver, owner, version, and external reachability; document non-applicability with evidence. https://nvd.nist.gov/vuln/detail/CVE-2026-74997

    Post summary

    The text outlines a general triage strategy for Roundcube CVE‑2026‑74997, recommending inventory of plugin components and documentation of non‑applicability, but it does not provide or reference any technical, exploit, or patch details.

    0000044
    86 followersView on X
  • iSECTECH@isectech_
    Patch

    Roundcube CVE-2026-74997 is configuration-dependent: RCE applies when markasjunk uses cmd_learn. Confirm configuration first, then patch affected systems to 1.6.18 or 1.7.3. https://roundcube.net/news/2026/08/09/security-updates-1.6.18-and-1.7.3

    Post summary

    The message highlights a configuration‑dependent RCE in Roundcube CVE-2026-74997 and recommends applying the latest patches (1.6.18 or 1.7.3).

    0000033
    86 followersView on X
  • ADK Cyber@ADKCyber
    Patch

    CVE-2026-74997 (CVSS 8.8) enables remote code execution in Roundcube Webmail before 1.6.18 or 1.7.3. Organizations using it should apply updates promptly. via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning https://t.co/m83g07Mww7

    Post summary

    The tweet announces CVE‑2026‑74997, a high‑severity remote code execution flaw in Roundcube Webmail, and urges users to apply the latest updates.

    0000052
    93 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Approundcubewebmail---

Explore more