Roundcube security advisory (AV26-793)
Serial number: AV26-793 Date: August 10, 2026 On August 9, 2026, Roundcube is affected by vulnerabilities in the following product: Roundcube Webmail prior to 1.6.18 prior to 1.7.3 The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates. Security updates 1.6.18 and 1.7.3 released Roundcube Webmail 1.6.18 Roundcube Webmail 1.7.3 Roundcube Open Source Webmail Software
CSIRTS triage
- What
- Roundcube Webmail contains vulnerabilities in versions before 1.6.18 and 1.7.3.
- Who is affected
- Organizations and individuals running Roundcube Webmail versions prior to 1.6.18 (legacy branch) or 1.7.3 (current branch).
- Urgency
- Severity unknown; no exploitation status or CVE details provided, limiting immediate risk assessment.
- Action
- Upgrade Roundcube Webmail to version 1.6.18 or 1.7.3 or later as appropriate for your branch.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Roundcube Webmail
Get an email when a new Roundcube Webmail advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/roundcube-security-advisory-av26-793
More from Canadian Centre for Cyber Security
- unknownWatchGuard security advisory (AV26-847)2026-08-25
- unknownOpenSSL security advisory (AV26-846)2026-08-25
- unknownGitea security advisory (AV26-845)2026-08-25
- unknownGoogle security advisory (AV26-844)2026-08-24
- criticalOracle security advisory – January 2026 quarterly rollup (AV26-042) – Update 22026-08-24