Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

openSUSE Roundcubemail Important Security Update 2026-0071-1

opensuse
Calendar Grey March 5, 2026
Dist Opensuse Esm H88
Recent updates for openSUSE Roundcube include critical security fixes addressing CSS injection and remote image blocking issues.
An update that fixes four vulnerabilities is now available.

Description

This update for roundcubemail fixes the following issues:

- update to 1.6.13 This is a security update to the stable version 1.6 of

Roundcube Webmail. It provides fixes to recently reported security

vulnerabilities:

+ Fix CSS injection vulnerability reported by CERT Polska (boo#1258052,

CVE-2026-26079).

+ Fix remote image blocking bypass via SVG content reported by

nullcathedral (boo#1257909, CVE-2026-25916). This version is

considered stable and we recommend to update all productive

installations of Roundcube 1.6.x with it. Please do backup your data

before updating! CHANGELOG

+ Managesieve: Fix handling of string-list format values for date tests

in Out of Office (#10075)

+ Fix CSS injection vulnerability reported by CERT Polska.

+ Fix remote image blocking bypass via SVG content reported by

nullcathedral.

- update to 1.6.12 This is a security update to the stable version 1.6 of

...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP6:

zypper in -t patch openSUSE-2026-71=1

Package List

- openSUSE Backports SLE-15-SP6 (noarch):

roundcubemail-1.6.13-bp156.2.12.1

References

https://www.suse.com/security/cve/CVE-2025-68460.html

https://www.suse.com/security/cve/CVE-2025-68461.html

https://www.suse.com/security/cve/CVE-2026-25916.html

https://www.suse.com/security/cve/CVE-2026-26079.html

https://bugzilla.suse.com/1255306

https://bugzilla.suse.com/1255308

https://bugzilla.suse.com/1257909

https://bugzilla.suse.com/1258052

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2026:0071-1
Rating: important
Affected Products: openSUSE Backports SLE-15-SP6

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here