https://seclists.org/oss-sec/2026/q3/203: CVE-2026-54432+moRoundcube XSS/SSRF/etc prior to 1.6.17/1.7.2
Published Jul 22, 2026
·Updated
Affected Software
1 affected component
roundcube<1.6.17, <1.7.2
Frequently Asked Questions
1
What is the severity of CVE-2026-54432?
CVE-2026-54432 has been classified as a medium severity vulnerability due to its potential for XSS and SSRF attacks.
2
How do I fix CVE-2026-54432?
To fix CVE-2026-54432, upgrade Roundcube to version 1.6.17 or 1.7.2 as these versions contain the necessary security patches.
3
What types of vulnerabilities are associated with CVE-2026-54432?
CVE-2026-54432 is associated with Cross-Site Scripting (XSS) and Server-Side Request Forgery (SSRF) vulnerabilities.
4
When was CVE-2026-54432 published?
CVE-2026-54432 was published on July 22, 2026.
5
Which versions of Roundcube are affected by CVE-2026-54432?
Versions of Roundcube prior to 1.6.17 and 1.7.2 are affected by CVE-2026-54432.