Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
CVE-2026-54432
Bohdan Kurinnoy discovered that attachment MIME types were neither
sanitized nor escaped on the attachment-validation warning page,
yielding a stored XSS vulnerability.
CVE-2026-54433
Bohdan Kurinnoy discovered that plain-text rendering was subject to
a zero-click stored XSS vulnerability via crafted mailto: URIs.
CVE-2026-62641
It was discovered that the TNEF decoder was subject to Denial of
Service via crafted compressed-RTF size in the winmail.dat
attachment file.
CVE-2026-62642
An infinite loop was discovered in the TNEF decoder, which may lead
to denial of service upon opening an email with a TNEF attachment.
CVE-2026-62643
It was discovered that the CSS sanitization fixes for CVE-2026-35540 and
CVE-2026-48843 were insufficient, allowing a malicious embedded
stylesheet in an HTML email to lead to SSRF or information
disclosure.
CVE-2026-62644
It was discovered that the password plugin was subject to username
Get the latest Linux and open source security news straight to your inbox.