PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-35540 Roundcube CVE debrief

CVE-2026-35540 is a vulnerability in Roundcube Webmail versions 1.6.0 before 1.6.14. The issue involves insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages, which may lead to Server-Side Request Forgery (SSRF) or Information Disclosure. This vulnerability has a CVSS score of 5.4 and a severity rating of MEDIUM. The vulnerability affects Roundcube Webmail versions from 1.6.0 up to but not including 1.6.14. Organizations using Roundcube Webmail versions 1.6.0 through 1.6.13 should prioritize updating to version 1.6.14 or applying the provided patches. The CVE record was published on 2026-04-03T05:16:22.100Z and was last modified on 2026-07-24T21:10:00.143Z.

Vendor
Roundcube
Product
Webmail
CVSS
MEDIUM 5.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-03
Original CVE updated
2026-07-24
Advisory published
2026-04-03
Advisory updated
2026-07-24

Who should care

Organizations using Roundcube Webmail versions 1.6.0 through 1.6.13 should prioritize updating to version 1.6.14 or applying the provided patches. This vulnerability could potentially allow attackers to access local network resources or disclose sensitive information.

Technical summary

The vulnerability arises from inadequate sanitization of CSS stylesheets in HTML e-mail messages. Attackers could exploit this by crafting malicious e-mails that include stylesheet links pointing to local network hosts, potentially leading to SSRF or information disclosure. The CVSS vector for this vulnerability is CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may allow attackers to access local network resources or disclose sensitive information. The vulnerability has a CVSS score of 5.4 and a severity rating of MEDIUM.

Defensive priority

Medium priority should be given to applying the necessary patches or updates, as the vulnerability's CVSS score of 5.4 indicates a moderate level of severity. Organizations should ensure that their Roundcube Webmail installations are updated to version 1.6.14 or later.

Recommended defensive actions

  • Apply the patches provided by Roundcube for versions 1.6.0 through 1.6.13.
  • Update Roundcube Webmail to version 1.6.14 or later.
  • Implement additional monitoring for suspicious e-mail activity.
  • Review and restrict access to local network resources.
  • Consider implementing compensating controls such as web application firewalls.

Evidence notes

The CVE record was published on 2026-04-03T05:16:22.100Z and was last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Analyzed. The vulnerability affects Roundcube Webmail versions from 1.6.0 up to but not including 1.6.14.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-35540 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-35540

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-35540 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-35540

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.