Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY43 SECURITY RECORDS

roundcube

webmail

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

This CVE identity is linked to the Lifecycle record Roundcube Webmail. Use that record for publisher support phases and retirement dates.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2026-75010 17 Aug 2026 1.6.0 < 1.6.18; 1.7.0 < 1.7.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-75007 17 Aug 2026 1.6.0 < 1.6.18; 1.7.0 < 1.7.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-75006 17 Aug 2026 1.6.0 < 1.6.18; 1.7.0 < 1.7.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-75004 17 Aug 2026 1.6.0 < 1.6.18; 1.7.0 < 1.7.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-75003 17 Aug 2026 1.6.0 < 1.6.18; 1.7.0 < 1.7.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-75002 17 Aug 2026 1.6.0 < 1.6.18; 1.7.0 < 1.7.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-75000 17 Aug 2026 1.6.0 < 1.6.18; 1.7.0 < 1.7.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-74999 17 Aug 2026 1.6.0 < 1.6.18; 1.7.0 < 1.7.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-74998 17 Aug 2026 1.6.0 < 1.6.18; 1.7.0 < 1.7.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-74997 17 Aug 2026 1.6.0 < 1.6.18; 1.7.0 < 1.7.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-54432 14 Jul 2026 1.6.0 < 1.6.17; 1.7.0 < 1.7.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-54433 14 Jul 2026 1.6.0 < 1.6.17; 1.7.0 < 1.7.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-62644 14 Jul 2026 1.6.0 < 1.6.17; 1.7.0 < 1.7.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-62643 14 Jul 2026 1.6.0 < 1.6.17; 1.7.0 < 1.7.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-62642 14 Jul 2026 1.6.0 < 1.6.17; 1.7.0 < 1.7.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-62641 14 Jul 2026 1.6.0 < 1.6.17; 1.7.0 < 1.7.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-48849 25 May 2026 1.6.0 < 1.6.16; 1.7.0 < 1.7.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-48848 25 May 2026 1.6.0 < 1.6.16; 1.7.0 < 1.7.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-48847 25 May 2026 1.6.0 < 1.6.16; 1.7.0 < 1.7.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-48846 25 May 2026 1.6.0 < 1.6.16; 1.7.0 < 1.7.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-48845 25 May 2026 1.6.14 < 1.6.16; 1.7.0 < 1.7.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-48844 25 May 2026 1.6.0 < 1.6.16; 1.7.0 < 1.7.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-48843 25 May 2026 1.6.14 < 1.6.16; 1.7.0 < 1.7.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-48842 25 May 2026 Webmail: 1.6.0 < 1.6.16, 1.7.0 < 1.7.1 No fixed version is explicitly recorded in the structured CVE data. Update reference ↗
CVE-2026-35545 3 Apr 2026 < 1.5.15; 1.6.0 < 1.6.15 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-35544 3 Apr 2026 < 1.5.14; 1.6.0 < 1.6.14 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-35543 3 Apr 2026 < 1.5.14; 1.6.0 < 1.6.14 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-35542 3 Apr 2026 < 1.5.14; 1.6.0 < 1.6.14 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-35541 3 Apr 2026 < 1.5.14; 1.6.0 < 1.6.14 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-35540 3 Apr 2026 1.6.0 < 1.6.14 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-35539 3 Apr 2026 < 1.5.14; 1.6.0 < 1.6.14 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-35538 3 Apr 2026 < 1.5.14; 1.6.0 < 1.6.14 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-35537 3 Apr 2026 < 1.5.14; 1.6.0 < 1.6.14 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-26079 11 Feb 2026 < 1.5.13; 1.6.0 < 1.6.13 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-25916 9 Feb 2026 < 1.5.13; 1.6.0 < 1.6.13 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-68461 18 Dec 2025 Webmail: < 1.5.12, 1.6.0 < 1.6.12 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2025-68460 18 Dec 2025 < 1.5.12; 1.6.0 < 1.6.12 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2025-49113 2 Jun 2025 Webmail: < 1.5.10, 1.6.0 < 1.6.11 The Cyber Centre strongly recommends that organizations update to Roundcube Webmail versions 1.5.10+ or 1.6.11+ Footnote 2 , which would mitigate issues reported by both CVEs mentioned here (CVE-2024-42009 and CVE-2025-49113). The Cyber Centre recommends that organizations: Assess the installation of Roundcube Webmail. Apply updates to Roundcube Webmail without delay. Monitor affected systems for signs of exploitation. Monitor for brute-force attempts and if possible, implement rate limitation techniques. In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre's Top 10 IT Security Actions Footnote 6 with an emphasis on the following strategies: If activity matching the content of this alert is discovered, recipients are encouraged to report via the My Cyber Portal , or email contact@cyber.gc.ca . Update reference ↗
CVE-2024-42009 5 Aug 2024 n/a The Cyber Centre strongly recommends that organizations update to Roundcube Webmail versions 1.5.10+ or 1.6.11+ Footnote 2 , which would mitigate issues reported by both CVEs mentioned here (CVE-2024-42009 and CVE-2025-49113). The Cyber Centre recommends that organizations: Assess the installation of Roundcube Webmail. Apply updates to Roundcube Webmail without delay. Monitor affected systems for signs of exploitation. Monitor for brute-force attempts and if possible, implement rate limitation techniques. In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre's Top 10 IT Security Actions Footnote 6 with an emphasis on the following strategies: If activity matching the content of this alert is discovered, recipients are encouraged to report via the My Cyber Portal , or email contact@cyber.gc.ca . Update reference ↗
CVE-2024-37383 7 Jun 2024 webmail: < 1.5.7, 1.6.0 < 1.6.7 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2023-5631 18 Oct 2023 Roundcubemail: 1.6.0 < 1.6.3, 1.5.0 < 1.5.4, 1.4.0 < 1.5.14 Roundcubemail: 1.6.4, 1.5.5, 1.5.15 Update reference ↗
CVE-2023-43770 22 Sep 2023 webmail: < 1.4.14, 1.5.0 < 1.5.4, 1.6.0 < 1.6.3; debian linux: 10 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2020-13965 9 Jun 2020 webmail: < 1.3.12, 1.4.0 < 1.4.5 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.