RoundCube DOO A.I CyberSecurity Scoring
RoundCube DOO
Company Information
Website:https://roundcube.rs
Employees number:10
Number of followers:163
NAICS:5112
Industry Type:Software Development
Homepage:roundcube.rs
RoundCube DOO Risk Score (AI oriented)
Between 700 and 749
RoundCube DOOSoftware Development
Updated:
09/07/2026
09/07/2026
742/1000
Moderate
Ba
RoundCube DOO Global Score (TPRM)
xxxx
RoundCube DOOSoftware Development
Score locked

RoundCube DOOModerate
Current Score
742Ba (MODERATE)
01000
3 incidents
-5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
742
JULY 2026
747
Vulnerability
01 Jul 2026 • RoundCube DOO
Roundcube: RoundCube 0-Click Vulnerability Enables Stored XSS Attack via MIME Type Attachment
Roundcube Patches Critical Zero-Click XSS Vulnerabilities in Version 1.7
742
CRITICAL-5
ROU1783621569
Roundcube Patches Critical Zero-Click XSS Vulnerabilities in Version 1.7
Roundcube has released version 1.7 to address six security vulnerabilities, including two critical stored cross-site scripting (XSS) flaws that enable zero-click exploitation. The most severe, CVE-2026-54432, allows attackers to execute arbitrary JavaScript by crafting a malicious MIME type in an email attachment, triggering the payload when a user views the attachment warning page without requiring any interaction. A related flaw, CVE-2026-54433, exploits Roundcube’s plain-text rendering engine, silently executing malicious scripts when a victim reads an email in plain-text mode.
Both vulnerabilities were discovered by Bohdan Kurinnoy of Samsung R&D Institute Ukraine (SRUKR), underscoring the growing focus on webmail platforms as prime targets for credential theft and session hijacking. Additional fixes in the update include patches for a TNEF decoder infinite loop (DoS), password plugin session-injection flaws, SSRF bypasses, and a DoS vulnerability in compressed-RTF attachments.
Beyond security, Roundcube 1.7 resolves stability issues, including OAuth password claim retrieval errors, vCard 2.1 import bugs, and Imagick temporary file leaks. Due to the zero-click nature of the XSS flaws, Roundcube has urged administrators to prioritize the update, particularly for externally exposed instances, to prevent session hijacking and unauthorized mailbox access. A full data backup is recommended before patching.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
JUNE 2026
747
MAY 2026
746
APRIL 2026
746
MARCH 2026
746
FEBRUARY 2026
750
Vulnerability
08 Feb 2026 • RoundCube DOO
Roundcube: Roundcube Webmail Vulnerability Let Attackers Track Email Opens
Roundcube Patches Critical Privacy Bypass Vulnerability in Webmail Software
745
LOW-5
ROU1770638099
Roundcube Patches Critical Privacy Bypass Vulnerability in Webmail Software
Roundcube, a widely used open-source webmail platform, has released urgent security updates to fix a privacy bypass flaw that allowed attackers to track email opens despite user settings blocking remote images. The vulnerability, disclosed by security researchers at NULL CATHEDRAL on February 8, 2026, affects all versions prior to 1.5.13 and 1.6.x versions before 1.6.13.
The issue stemmed from a flaw in Roundcube’s HTML sanitizer, rcube_washtml, which failed to recognize the SVG element `<feImage>` as an image container. While the sanitizer blocked standard image tags (e.g., `<img>`), it treated `<feImage>` an SVG filter primitive that fetches external resources via the `href` attribute as a regular hyperlink. This allowed attackers to embed invisible 1×1 SVGs in emails, triggering automatic GET requests to attacker-controlled servers when the email was rendered.
Exploiting this flaw enabled threat actors to:
- Confirm active email addresses.
- Log recipients’ IP addresses.
- Fingerprint browsers and devices.
The patch, implemented in commit 26d7677, updates the sanitizer’s regex logic to explicitly block `<feImage>` alongside other image-related tags. Administrators of self-hosted Roundcube instances are advised to upgrade to 1.5.13 or 1.6.13 to mitigate the risk.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JANUARY 2026
750
DECEMBER 2025
750
NOVEMBER 2025
750
OCTOBER 2025
750
SEPTEMBER 2025
750
JUNE 2025
752
Vulnerability
01 Jun 2025 • RoundCube DOO
Roundcube
Critical RCE Flaw in Roundcube Webmail (CVE-2025-49113)
749
CRITICAL-3
ROU300060925
Over 84,000 Roundcube webmail installations are vulnerable to CVE-2025-49113, a critical remote code execution (RCE) flaw with a public exploit. The flaw, which impacts Roundcube versions 1.1.0 through 1.6.10, was patched on June 1, 2025. Hackers have reverse-engineered the patch to develop a working exploit, sold on underground forums. The vulnerability stems from unsanitized $_GET['_from'] input, enabling PHP object deserialization and session corruption. Although exploitation requires authentication, attackers claim valid credentials can be obtained via CSRF, log scraping, or brute-forcing. The high risk of exploitation and potential for data theft make the exposure of these instances a significant cybersecurity risk.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for RoundCube DOO ??
What was RoundCube DOO's A.I Rankiteo Cyber Score in July 2026 ??
What was RoundCube DOO's A.I Rankiteo Cyber Score in June 2026 ??
What was RoundCube DOO's A.I Rankiteo Cyber Score in May 2026 ??
What was RoundCube DOO's A.I Rankiteo Cyber Score in April 2026 ??
What was RoundCube DOO's A.I Rankiteo Cyber Score in March 2026 ??
What was RoundCube DOO's A.I Rankiteo Cyber Score in February 2026 ??
What was RoundCube DOO's A.I Rankiteo Cyber Score in January 2026 ??
What was RoundCube DOO's A.I Rankiteo Cyber Score in December 2025 ??
What was RoundCube DOO's A.I Rankiteo Cyber Score in November 2025 ??
What was RoundCube DOO's A.I Rankiteo Cyber Score in October 2025 ??
What was RoundCube DOO's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on RoundCube DOO's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with RoundCube DOO ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view RoundCube DOO's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?