Post
Suriq - Always on Watch
suriq.io
did:plc:6vjp7fbgz5ductueireifliv
Roundcube Webmail has a command-injection flaw (CVE-2026-74997, CVSS 8.8): a logged-in user can run commands on the mail server.
It only bites installs using the markasjunk plugin's cmd_learn spam training.
Fixed in 1.6.18 and 1.7.3. Patch now.
https://suriq.io/blog/roundcube-markasjunk-command-injection-cve-2026-74997
2026-08-17T13:12:11.971Z