CVE-2026-74998
EUVD-2026-6016517.08.2026, 13:16
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information disclosure or XSS (cross-site scripting) via MIME sniffing.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| roundcube | webmail | 1.6.0 ≤ 𝑥 < 1.6.18 | CNA |
| roundcube | webmail | 1.7.0 ≤ 𝑥 < 1.7.3 | CNA |
Debian Releases
References