PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-35539 Roundcube CVE debrief

A medium-severity XSS vulnerability was discovered in Roundcube Webmail before versions 1.5.14 and 1.6.14. The issue arises from insufficient HTML attachment sanitization in preview mode, allowing attackers to execute malicious scripts when a victim previews a text/html attachment. This vulnerability has been publicly disclosed and patches are available. Administrators should prioritize patching to prevent potential XSS attacks.

Vendor
Roundcube
Product
Webmail
CVSS
MEDIUM 6.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-03
Original CVE updated
2026-07-24
Advisory published
2026-04-03
Advisory updated
2026-07-24

Who should care

Administrators and users of Roundcube Webmail versions prior to 1.5.14 and 1.6.14 should apply the necessary patches to prevent potential XSS attacks. Additionally, security teams and vulnerability management teams should review the vulnerability and assess their exposure.

Technical summary

CVE-2026-35539 is a medium-severity XSS vulnerability in Roundcube Webmail before versions 1.5.14 and 1.6.14. The vulnerability exists due to insufficient HTML attachment sanitization in preview mode. An attacker can exploit this vulnerability by sending a malicious text/html attachment to a victim, who then previews the attachment, allowing the attacker to execute arbitrary JavaScript code in the context of the victim's session. This vulnerability has been publicly disclosed and patches are available.

Defensive priority

Medium priority should be given to applying patches for Roundcube Webmail versions prior to 1.5.14 and 1.6.14 to prevent potential XSS attacks. Additionally, security teams should review the vulnerability and assess their exposure.

Recommended defensive actions

  • Apply patches for Roundcube Webmail versions 1.5.14 and 1.6.14.
  • Restrict user access to previewing attachments.
  • Implement additional security measures such as input validation and output encoding.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record was published on 2026-04-03T05:16:21.920Z and was last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Analyzed. This information is based on the provided source corpus. Further verification is recommended to ensure accuracy.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-03T05:16:21.920Z and has not been modified since then. The NVD entry is currently Analyzed.