PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-35540 Roundcube CVE debrief

CVE-2026-35540 is a vulnerability in Roundcube Webmail versions 1.6.0 before 1.6.14. The issue involves insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages, which may lead to Server-Side Request Forgery (SSRF) or Information Disclosure. This vulnerability has a CVSS score of 5.4 and a severity rating of MEDIUM. The vulnerability affects Roundcube Webmail versions from 1.6.0 up to but not including 1.6.14. Organizations using Roundcube Webmail versions 1.6.0 through 1.6.13 should prioritize updating to version 1.6.14 or applying the provided patches. The CVE record was published on 2026-04-03T05:16:22.100Z and was last modified on 2026-07-24T21:10:00.143Z.

Vendor
Roundcube
Product
Webmail
CVSS
MEDIUM 5.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-03
Original CVE updated
2026-07-24
Advisory published
2026-04-03
Advisory updated
2026-07-24

Who should care

Organizations using Roundcube Webmail versions 1.6.0 through 1.6.13 should prioritize updating to version 1.6.14 or applying the provided patches. This vulnerability could potentially allow attackers to access local network resources or disclose sensitive information.

Technical summary

The vulnerability arises from inadequate sanitization of CSS stylesheets in HTML e-mail messages. Attackers could exploit this by crafting malicious e-mails that include stylesheet links pointing to local network hosts, potentially leading to SSRF or information disclosure. The CVSS vector for this vulnerability is CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may allow attackers to access local network resources or disclose sensitive information. The vulnerability has a CVSS score of 5.4 and a severity rating of MEDIUM.

Defensive priority

Medium priority should be given to applying the necessary patches or updates, as the vulnerability's CVSS score of 5.4 indicates a moderate level of severity. Organizations should ensure that their Roundcube Webmail installations are updated to version 1.6.14 or later.

Recommended defensive actions

  • Apply the patches provided by Roundcube for versions 1.6.0 through 1.6.13.
  • Update Roundcube Webmail to version 1.6.14 or later.
  • Implement additional monitoring for suspicious e-mail activity.
  • Review and restrict access to local network resources.
  • Consider implementing compensating controls such as web application firewalls.

Evidence notes

The CVE record was published on 2026-04-03T05:16:22.100Z and was last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Analyzed. The vulnerability affects Roundcube Webmail versions from 1.6.0 up to but not including 1.6.14.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-03T05:16:22.100Z and has not been modified since then. The NVD entry is currently Analyzed.