CVE-2026-26079: Roundcube Webmail

Medium severity, CVSS 4.7. EPSS: 0.6% chance of exploitation in the next 30 days.

Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13 allows Cascading Style Sheets (CSS) injection, e.g., because comments are mishandled.

Affected products

  • Roundcube Webmail: before 1.5.13 (fixed in 1.5.13); from 1.6.0, before 1.6.13 (fixed in 1.6.13)

Published 2026-02-11. Last modified 2026-06-17.