Roundcube security advisory (AV26-503) – Update 1

Serial number: AV26-503
Date: May 25, 2026
Updated: September 21, 2026

On May 24, 2026, Roundcube published security advisories to address vulnerabilities in the following product: 

  • Roundcube Webmail – versions prior to 1.6.16
  • Roundcube Webmail – versions prior to 1.7.1

Update 1

Open-source reporting indicates that CVE-2026-48842 is being exploited in the wild.

The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.

Date modified: