High severity7.2OSV Advisory· Published Jul 14, 2026· Updated Jul 17, 2026
CVE-2026-54433
CVE-2026-54433
Description
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the victim's authenticated session simply by opening or previewing the message (zero-click).
Affected products
3- Range: <1.6.17, <1.7.2
Patches
Vulnerability mechanics
References
1- roundcube.net/news/2026/07/05/security-updates-1.6.17-and-1.7.2nvdVendor Advisory
News mentions
2- Cyber Security Newsletter and Bulletin Weekly – 16-Year-Old Linux, Ubiquiti Flaws, Accenture Breach, Android 17 Exploit +20 StoriesCyber Security News · Jul 12, 2026
- RoundCube 0-Click Vulnerability Enables Stored XSS Attack via MIME Type AttachmentCyber Security News · Jul 9, 2026