Roundcube Patches 11 Critical Vulnerabilities in Emergency 1.6.18 and 1.7.3 Update

Published by

Roundcube has issued emergency updates for versions 1.6.18 and 1.7.3, addressing eleven critical vulnerabilities, including unauthenticated remote code execution and pre-authentication IMAP command injection. Security researchers highlight that persistent HTML sanitization issues suggest deeper architectural problems that require more than just incremental patches. Administrators are urged to update immediately and disable the markasjunk plugin if not in use, as it poses significant security risks. The situation reflects ongoing exploitation pressures, with Roundcube rolling out frequent updates to protect users from various attack vectors



Roundcube Patches 11 Critical Vulnerabilities in Emergency 1.6.18 and 1.7.3 Update

Roundcube has released emergency updates for both its LTS and current stable branches, scrubbing eleven distinct security flaws from versions 1.6.18 and 1.7.3. The patch closes critical attack paths including unauthenticated RCE via the markasjunk plugin, pre-authentication IMAP command injection, Sieve and LDAP filter injection, plus multiple SSRF and persistent XSS bypasses. Security researchers note that the recurring HTML sanitization failures point to a deeper architectural flaw that incremental patches can no longer contain. Administrators should update immediately and disable the markasjunk plugin if it isn't actively needed.

Roundcube Patches 11 Critical Vulnerabilities in Emergency 1.6.18 and 1.7.3 Update @ Linux Compatible