CVE-2026-35538
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injectio
CVSS
3.1
Bajo
EPSS
0.3%
p27
KEV
—
Exploit Today
8
0-100
Publicado: 3 abr 2026 · Última mod.: 24 jul 2026 · CWE-88
0.3%EPSS · 30 días0.3%
2026-08-182026-09-14
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search.
- github.comhttps://github.com/roundcube/roundcubemail/commit/5fe8a69956a9683a4269f3ad2a68e18deebf8a15
- github.comhttps://github.com/roundcube/roundcubemail/commit/7daf5aa9c190ccc75bb31672d8fee9938877fd64
- github.comhttps://github.com/roundcube/roundcubemail/commit/b18a8fa8e81571914c0ff55d4e20edb459c6952c
- github.comhttps://github.com/roundcube/roundcubemail/releases/tag/1.5.14
- github.comhttps://github.com/roundcube/roundcubemail/releases/tag/1.6.14
- github.comhttps://github.com/roundcube/roundcubemail/releases/tag/1.7-rc5
- roundcube.nethttps://roundcube.net/news/2026/03/18/security-updates-1.7-rc5-1.6.14-1.5.14
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-196247.8 ALT—
——0A flaw was found in NetworkManager-l2tp. The plugin writes attacker-controlled VPN connection properties (vpn.data and vpn.secrets values) unescaped into a generated ipsec.conf file that pluto loads as root. A local unprivileged user can create and activate their own L2TP VPN profile containing a newline-injected leftupdown directive; pluto executes that command as root when the IKE security association is established, resulting in local privilege escalation. This is the same bug class as CVE-2018-10900 (NetworkManager-vpnc).2dCVE-2026-908097.3 ALT—
——0A vulnerability was identified in HKUDS nanobot up to 0.2.1. The affected element is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component ExecTool. Such manipulation leads to argument injection. It is possible to launch the attack remotely. The name of the patch is af582246f141311d574551b7571a517bcc3df750. It is best practice to apply a patch to resolve this issue.19hCVE-2026-908947.8 ALT—
——0Parallels Desktop runs prl_disp_service as root. Local clients reach it on the world-writable socket /var/run/prl_disp_service.socket. PrlSrv_LoginLocal accepts peer credentials. No Parallels signature. No admin group.
After login, PrlSrv_InstallAppliance lets you pick the appliance folder (sVmParentPath). The daemon unpacks with one string, tar -xf "%1" -C "%2", then Qt QProcess::splitCommand chops that string into words. A quote in the folder name closes early. The leftover text becomes extra tar flags. macOS tar --use-compress-program= runs the named program as root.1dCVE-2023-226322.7 BAJ13.2%
——4PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the FTP Server Count Sensor.2dCVE-2023-226312.7 BAJ13.2%
——4PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the HTTP XML/REST Sensor.2dCVE-2026-904674.0 MED13.7%
——4aiosmtplib before 5.1.3 fails to properly validate email addresses supplied by callers, allowing attackers to inject ESMTP parameters into MAIL FROM and RCPT TO command lines. Attackers can craft malicious addresses containing spaces and angle brackets to append parameters like AUTH, NOTIFY, or ORCPT to envelope commands, forging authenticated identities or forcing delivery notifications to third parties.2d