Medium severity4.7NVD Advisory· Published Jul 14, 2026· Updated Jul 15, 2026
CVE-2026-54432
CVE-2026-54432
Description
Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS). The issue occurs because the attachment MIME type is not properly escaped on the attachment-validation warning page.
Affected products
2- Range: <1.6.17, <1.7.2
Patches
Vulnerability mechanics
References
1News mentions
3- ⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and MoreThe Hacker News · Jul 13, 2026
- Cyber Security Newsletter and Bulletin Weekly – 16-Year-Old Linux, Ubiquiti Flaws, Accenture Breach, Android 17 Exploit +20 StoriesCyber Security News · Jul 12, 2026
- RoundCube 0-Click Vulnerability Enables Stored XSS Attack via MIME Type AttachmentCyber Security News · Jul 9, 2026