PatchSiren cyber security CVE debrief
CVE-2026-35540 Roundcube CVE debrief
CVE-2026-35540 is a vulnerability in Roundcube Webmail versions 1.6.0 before 1.6.14. The issue involves insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages, which may lead to Server-Side Request Forgery (SSRF) or Information Disclosure. This vulnerability has a CVSS score of 5.4 and a severity rating of MEDIUM. The vulnerability affects Roundcube Webmail versions from 1.6.0 up to but not including 1.6.14. Organizations using Roundcube Webmail versions 1.6.0 through 1.6.13 should prioritize updating to version 1.6.14 or applying the provided patches. The CVE record was published on 2026-04-03T05:16:22.100Z and was last modified on 2026-07-24T21:10:00.143Z.
- Vendor
- Roundcube
- Product
- Webmail
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-03
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-03
- Advisory updated
- 2026-07-24
Who should care
Organizations using Roundcube Webmail versions 1.6.0 through 1.6.13 should prioritize updating to version 1.6.14 or applying the provided patches. This vulnerability could potentially allow attackers to access local network resources or disclose sensitive information.
Technical summary
The vulnerability arises from inadequate sanitization of CSS stylesheets in HTML e-mail messages. Attackers could exploit this by crafting malicious e-mails that include stylesheet links pointing to local network hosts, potentially leading to SSRF or information disclosure. The CVSS vector for this vulnerability is CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may allow attackers to access local network resources or disclose sensitive information. The vulnerability has a CVSS score of 5.4 and a severity rating of MEDIUM.
Defensive priority
Medium priority should be given to applying the necessary patches or updates, as the vulnerability's CVSS score of 5.4 indicates a moderate level of severity. Organizations should ensure that their Roundcube Webmail installations are updated to version 1.6.14 or later.
Recommended defensive actions
- Apply the patches provided by Roundcube for versions 1.6.0 through 1.6.13.
- Update Roundcube Webmail to version 1.6.14 or later.
- Implement additional monitoring for suspicious e-mail activity.
- Review and restrict access to local network resources.
- Consider implementing compensating controls such as web application firewalls.
Evidence notes
The CVE record was published on 2026-04-03T05:16:22.100Z and was last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Analyzed. The vulnerability affects Roundcube Webmail versions from 1.6.0 up to but not including 1.6.14.
Official resources
-
CVE-2026-35540 CVE record
CVE.org
-
CVE-2026-35540 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Patch
-
Mitigation or vendor reference
[email protected] - Patch
-
Mitigation or vendor reference
[email protected] - Release Notes
-
Mitigation or vendor reference
[email protected] - Release Notes
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-03T05:16:22.100Z and has not been modified since then. The NVD entry is currently Analyzed.