Roundcube Project News - Latest Security News

We just published service and security updates to the stable version 1.4 and the LTS version 1.3 of Roundcube Webmail. They contain four fixes for recently reported security vulnerabilities as well a number of general improvements from our issue tracker.

Continue reading

We just published service and security updates to the stable version 1.4 and the LTS versions 1.3 and 1.2 of Roundcube Webmail. They contain four fixes for recently reported security vulnerabilities as well a number of general improvements from our issue tracker.

Continue reading

Phishing Alert

28 October 2019

We have been receiving many reports about phishing attempts appearing out in the wild which are targeting end users of webmail services powered by Roundcube.

Continue reading

We proudly announce the next service release to update the stable version 1.3.

Continue reading

Update 1.3.8 released

26 October 2018

We proudly announce the next service release to update the stable version 1.3.

Continue reading

We proudly announce the next service release to update the stable version 1.3. It contains fixes to several bugs backported from the master branch including a security fix mitigating the EFAIL issue recently discovered in OpenPGP.

Continue reading

Following the recent security update for 1.3, here now come the promised updates for the LTS versions 1.2 and 1.1. They both fix the recently reported vulnerability allowing IMAP command injection via a GET parameters. More details about this are published under CVE-2018-9846.

Continue reading

We just published a security update to the stable version 1.3. It primarily fixes a recently discovered IMAP command injection vulnerability caused by insufficient input validation within the archive plugin. Details about the vulnerability are published under CVE-2018-9846.

Continue reading

We just published updates to all stable versions from 1.1.x onwards delivering fixes for a recently discovered file disclosure vulnerability in Roundcube Webmail.

Continue reading

Update 1.2.6 released

10 September 2017

This is a service and security update to the stable version 1.2. It contains some important bug fixes and improvements which we picked from the upstream branch.

Continue reading
Return to News overview