CVE-2026-26079: Roundcube Webmail
Medium severity, CVSS 4.7. EPSS: 0.6% chance of exploitation in the next 30 days.
Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13 allows Cascading Style Sheets (CSS) injection, e.g., because comments are mishandled.
Affected products
- Roundcube Webmail: before 1.5.13 (fixed in 1.5.13); from 1.6.0, before 1.6.13 (fixed in 1.6.13)
Published 2026-02-11. Last modified 2026-06-17.