CVE-2026-75010
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication
CVSS
6.4
Medio
EPSS
0.3%
p20
KEV
—
Exploit Today
6
0-100
Publicado: 17 ago 2026 · Última mod.: 17 ago 2026 · CWE-669
0.3%EPSS · 30 días0.3%
2026-08-182026-08-30
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a user-controlled host via crafted session data. This issue only affects Roundcube instances using the password plugin with its modoboa driver.
- github.comhttps://github.com/roundcube/roundcubemail/commit/65b8ea9d8304b10f1d3bda5bcc82f9c682cf804c
- github.comhttps://github.com/roundcube/roundcubemail/commit/b0e26d617e7bbe3051135285993bc55f718fea2f
- github.comhttps://github.com/roundcube/roundcubemail/releases/tag/1.6.18
- github.comhttps://github.com/roundcube/roundcubemail/releases/tag/1.7.3
- roundcube.nethttps://roundcube.net/news/2026/08/09/security-updates-1.6.18-and-1.7.3
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-750035.8 MED23.0%
——7In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image blocking, which may lead to information disclosure or privilege escalation.13dCVE-2026-750005.8 MED24.7%
——7In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking bypass, which in turn may lead to information disclosure or privilege escalation.13dCVE-2026-735743.1 BAJ9.5%
——3In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Client due to improper validation of the fu request parameter. An unauthenticated attacker can exploit this vulnerability by supplying a crafted path, potentially allowing unauthorized disclosure of protected files, such as WEB-INF/web.xml, within the web application directory. This occurs in the Forward servlet.3dCVE-2026-711946.8 MED22.7%
——7In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOTIFY requests. When two zones with the same name exist across different pools, the lookup fails with a deterministic error, causing the handler to return REFUSED for all DNS queries through that path. The _handle_notify path is exploitable via a single unauthenticated UDP packet. This is independently reachable through the cross-tenant zone overlap described in a different recent CVE, and also affects legitimate same-tenant cross-pool configurations. BIND9 views do not mitigate this issue as mDNS is a shared service upstream of any view configuration.18dCVE-2026-732813.5 BAJ5.3%
——2In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.19dCVE-2026-141518.3 ALT25.7%
——8Inappropriate implementation in AI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)61d