PatchSiren cyber security CVE debrief
CVE-2026-35540 Roundcube CVE debrief
CVE-2026-35540 is a vulnerability in Roundcube Webmail versions 1.6.0 before 1.6.14. The issue involves insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages, which may lead to Server-Side Request Forgery (SSRF) or Information Disclosure. This vulnerability has a CVSS score of 5.4 and a severity rating of MEDIUM. The vulnerability affects Roundcube Webmail versions from 1.6.0 up to but not including 1.6.14. Organizations using Roundcube Webmail versions 1.6.0 through 1.6.13 should prioritize updating to version 1.6.14 or applying the provided patches. The CVE record was published on 2026-04-03T05:16:22.100Z and was last modified on 2026-07-24T21:10:00.143Z.
- Vendor
- Roundcube
- Product
- Webmail
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-03
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-03
- Advisory updated
- 2026-07-24
Who should care
Organizations using Roundcube Webmail versions 1.6.0 through 1.6.13 should prioritize updating to version 1.6.14 or applying the provided patches. This vulnerability could potentially allow attackers to access local network resources or disclose sensitive information.
Technical summary
The vulnerability arises from inadequate sanitization of CSS stylesheets in HTML e-mail messages. Attackers could exploit this by crafting malicious e-mails that include stylesheet links pointing to local network hosts, potentially leading to SSRF or information disclosure. The CVSS vector for this vulnerability is CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may allow attackers to access local network resources or disclose sensitive information. The vulnerability has a CVSS score of 5.4 and a severity rating of MEDIUM.
Defensive priority
Medium priority should be given to applying the necessary patches or updates, as the vulnerability's CVSS score of 5.4 indicates a moderate level of severity. Organizations should ensure that their Roundcube Webmail installations are updated to version 1.6.14 or later.
Recommended defensive actions
- Apply the patches provided by Roundcube for versions 1.6.0 through 1.6.13.
- Update Roundcube Webmail to version 1.6.14 or later.
- Implement additional monitoring for suspicious e-mail activity.
- Review and restrict access to local network resources.
- Consider implementing compensating controls such as web application firewalls.
Evidence notes
The CVE record was published on 2026-04-03T05:16:22.100Z and was last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Analyzed. The vulnerability affects Roundcube Webmail versions from 1.6.0 up to but not including 1.6.14.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-35540 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-35540
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-35540 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-35540
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/roundcube/roundcubemail/commit/27ec6cc9cb25e1ef8b4d4ef39ce76d619caa6870
[email protected] - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/roundcube/roundcubemail/commit/579b68eff90650a5c782e153debd66c765648942
[email protected] - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/roundcube/roundcubemail/releases/tag/1.6.14
[email protected] - Release Notes
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/roundcube/roundcubemail/releases/tag/1.7-rc5
[email protected] - Release Notes
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://roundcube.net/news/2026/03/18/security-updates-1.7-rc5-1.6.14-1.5.14
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.