Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 39 articles for you...
172

Ubuntu 26.04 LTS Roundcube Important XSS Risk USN-8482-1

Roundcube Webmail could be made to run programs as your login if it opened a malicious website.. ========================================================================== Ubuntu Security Notice USN-8482-1 June 30, 2026 roundcube vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS Summary: Roundcube Webmail could be made to run programs as your login if it opened a malicious website. Software Description: - roundcube: skinnable AJAX based webmail solution for IMAP servers - metapack Details: It was discovered that Roundcube Webmail was prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document. An attacker could use this issue to execute arbitrary web script in the context of an affected user's session. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS roundcube 1.6.11+dfsg-1ubuntu0.26.04.1~esm1 Available with Ubuntu Pro roundcube-core 1.6.11+dfsg-1ubuntu0.26.04.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8482-1 CVE-2025-68461 . Roundcube Webmail has a Cross-Site Scripting issue that could allow attackers to execute scripts via malicious websites. Update now.. Roundcube Webmail, Ubuntu security, XSS vulnerability, web application security, system update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 30, 2026 Important Ubuntu
172

Ubuntu 24.04 LTS 8223-1 Roundcube Critical Cross-Site Scripting

Several security issues were fixed in Roundcube Webmail.. ========================================================================== Ubuntu Security Notice USN-8223-1 April 29, 2026 roundcube vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in Roundcube Webmail. Software Description: - roundcube: skinnable AJAX based webmail solution for IMAP servers - metapackage Details: It was discovered that Roundcube Webmail mishandled Punycode xn-- domain names. An attacker could possibly use this issue to cause a homograph attack. (CVE-2019-15237) It was discovered that Roundcube Webmail did not properly sanitize certain attributes when handling CSS within HTML messages and certain SVG attributes. An attacker could possibly use this issue to cause a cross-site scripting attack. (CVE-2024-38356, CVE-2024-38357) It was discovered that Roundcube Webmail did not properly sanitize certain HTML attributes when rendering e-mail messages. An attacker could possibly use this issue to cause a cross-site scripting attack. (CVE-2024-42008) It was discovered that Roundcube Webmail did not properly filter certain CSS token sequences within rendered e-mail messages. An attacker could possibly use this issue to obtain sensitive information. (CVE-2024-42010) It was discovered that Roundcube Webmail did not properly treat an SVG tag as an image source within its HTML sanitizer. An attacker could possibly use this issue to bypass remote image blocking to track email open actions or potentially bypass access control. (CVE-2026-25916) It was discovered that Roundcube Webmail did not properly handle comments within Cascading Style Sheets (CSS). An attacker could possibly use this issue to perform a CSS injection attack. (CVE-2026-26079) Update instructions: The problem can becorrected by updating your system to the following package versions: Ubuntu 24.04 LTS roundcube-core 1.6.6+dfsg-2ubuntu0.1+esm3 Available with Ubuntu Pro Ubuntu 22.04 LTS roundcube-core 1.5.0+dfsg.1-2ubuntu0.1~esm6 Available with Ubuntu Pro roundcube-plugins 1.5.0+dfsg.1-2ubuntu0.1~esm6 Available with Ubuntu Pro Ubuntu 20.04 LTS roundcube-core 1.4.3+dfsg.1-1ubuntu0.1~esm8 Available with Ubuntu Pro roundcube-plugins 1.4.3+dfsg.1-1ubuntu0.1~esm8 Available with Ubuntu Pro Ubuntu 18.04 LTS roundcube-core 1.3.6+dfsg.1-1ubuntu0.1~esm8 Available with Ubuntu Pro roundcube-plugins 1.3.6+dfsg.1-1ubuntu0.1~esm8 Available with Ubuntu Pro Ubuntu 16.04 LTS roundcube-core 1.2~beta+dfsg.1-0ubuntu1+esm8 Available with Ubuntu Pro roundcube-plugins 1.2~beta+dfsg.1-0ubuntu1+esm8 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8223-1 CVE-2019-15237, CVE-2024-38356, CVE-2024-38357, CVE-2024-42008, CVE-2024-42010, CVE-2026-25916, CVE-2026-26079 . Numerous issues fixed in Roundcube Webmail for multiple Ubuntu versions. Important updates recommended for security.. Roundcube Webmail, Ubuntu update, HTML sanitation, security fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 29, 2026 Critical Ubuntu
87

Debian Roundcube Important DSA-6196-1 Multiple Vulnerabilities

Multiple vulnerabilities were discovered in roundcube, a skinnable AJAX based webmail solution for IMAP servers, which could result in information disclosure, IMAP injection, CSRF bypass, bypass of remote image blocking, cross-site scripting, access control bypass, or privilege escalation.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6196-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso April 04, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : roundcube CVE ID : CVE-2026-35537 CVE-2026-35538 CVE-2026-35539 CVE-2026-35540 CVE-2026-35541 CVE-2026-35542 CVE-2026-35543 CVE-2026-35544 CVE-2026-35545 Debian Bug : 1131182 1132268 Multiple vulnerabilities were discovered in roundcube, a skinnable AJAX based webmail solution for IMAP servers, which could result in information disclosure, IMAP injection, CSRF bypass, bypass of remote image blocking, cross-site scripting, access control bypass, or privilege escalation. For the oldstable distribution (bookworm), these problems have been fixed in version 1.6.5+dfsg-1+deb12u8. For the stable distribution (trixie), these problems have been fixed in version 1.6.15+dfsg-0+deb13u1. We recommend that you upgrade your roundcube packages. For the detailed security status of roundcube please refer to its security tracker page at: https://security-tracker.debian.org/tracker/roundcube Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Roundcube webmail faces multiple vulnerabilities leading to serious access and disclosure threat. Upgrade recommended for security.. Roundcube vulnerabilities, Debian DSA-6196-1,webmail security, access control issues, information leakage. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 04, 2026 Important Debian
172

Security Vulnerabilities in Roundcube Webmail for Ubuntu 18.04 USN-8132-1

Several security issues were fixed in Roundcube Webmail.. ========================================================================== Ubuntu Security Notice USN-8132-1 March 30, 2026 roundcube vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in Roundcube Webmail. Software Description: - roundcube: skinnable AJAX based webmail solution for IMAP servers - metapack Details: It was discovered that Roundcube Webmail did not properly sanitize certain HTML elements within the e-mail body. An attacker could possibly use this issue to cause a cross-site scripting attack. This issue was only addressed in Ubuntu 16.04 LTS. (CVE-2016-4068, CVE-2016-4069) It was discovered that Roundcube Webmail did not properly handle certain configuration parameters. An attacker could possibly use this issue to execute arbitrary code. This issue was only addressed in Ubuntu 16.04 LTS. (CVE-2016-9920) It was discovered that Roundcube Webmail did not properly sanitize CSS styles within SVG documents. An attacker could possibly use this issue to cause a cross-site scripting attack. This issue was only addressed in Ubuntu 16.04 LTS. (CVE-2017-6820) It was discovered that Roundcube Webmail did not properly restrict exec call in certain drivers of the password plugin. An authenticated user could possibly use this issue to perform arbitrary password resets. This issue was only addressed in Ubuntu 16.04 LTS. (CVE-2017-8114) It was discovered that Roundcube Webmail did not properly set file permissions within the Enigma plugin. An attacker could possibly use this issue to exfiltrate GPG private keys via network connectivity. (CVE-2018-1000071) It was discovered that Roundcube Webmail did not properly handle GnuPG MDC integrity-protection warnings. An attacker could possibly use this issue to obtain sensitive information fromencrypted communications. (CVE-2018-19205) It was discovered that Roundcube Webmail did not properly sanitize and tags within HTML attachments. An attacker could possibly use this issue to cause a cross-site scripting attack. (CVE-2018-19206) It was discovered that Roundcube Webmail did not properly handle partially encrypted multipart messages. An attacker could possibly use this issue to cause leaking of the plaintext of encrypted messages via an email reply. (CVE-2019-10740) It was discovered that Roundcube Webmail did not properly sanitize a certain parameter within the archive plugin. An attacker could possibly use this issue to perform an IMAP injection attack. This issue was only addressed in Ubuntu 16.04 LTS. (CVE-2018-9846) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS roundcube-core 1.3.6+dfsg.1-1ubuntu0.1~esm7 Available with Ubuntu Pro roundcube-plugins 1.3.6+dfsg.1-1ubuntu0.1~esm7 Available with Ubuntu Pro Ubuntu 16.04 LTS roundcube-core 1.2~beta+dfsg.1-0ubuntu1+esm7 Available with Ubuntu Pro roundcube-plugins 1.2~beta+dfsg.1-0ubuntu1+esm7 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8132-1 CVE-2016-4068, CVE-2016-4069, CVE-2016-9920, CVE-2017-6820, CVE-2017-8114, CVE-2018-1000071, CVE-2018-19205, CVE-2018-19206, CVE-2018-9846, CVE-2019-10740 . Several security issues in Roundcube Webmail for Ubuntu fixed. Update advised for affected versions immediately.. Roundcube Webmail Security, Ubuntu Vulnerabilities, Cross-Site Scripting Threats, IMAP Injection Risks. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 30, 2026 Important Ubuntu
172

Ubuntu 20.04 LTS Roundcube 1.4.3 Regression Fix CVE 2026-0001

USN-8097-1 introduced a regression in roundcube. ========================================================================== Ubuntu Security Notice USN-8097-2 March 18, 2026 roundcube regression ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS Summary: USN-8097-1 introduced a regression in roundcube Software Description: - roundcube: skinnable AJAX based webmail solution for IMAP servers - metapack Details: USN-8097-1 fixed a vulnerability in roundcube. The update caused a regression affecting the HTML sanitizer, preventing Roundcube from rendering any email message body. This update fixes the problem. We apologize for the inconvenience. Original advisory details: It was discovered that Roundcube Webmail did not properly sanitize the animate tag within SVG documents. An attacker could possibly use this issue to cause a cross-site scripting attack. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS roundcube-core 1.4.3+dfsg.1-1ubuntu0.1~esm7 Available with Ubuntu Pro roundcube-plugins 1.4.3+dfsg.1-1ubuntu0.1~esm7 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8097-2 https://ubuntu.com/security/notices/USN-8097-1 https://launchpad.net/bugs/2144682 . Roundcube security fix in Ubuntu 20.04 LTS addresses regression affecting email rendering and XSS.. Roundcube Security Fix, Ubuntu 20.04 LTS, XSS Vulnerability, HTML Sanitization Issue. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 18, 2026 Important Ubuntu
172

Ubuntu 24.04 Roundcube Moderate XSS Risk USN-8097-1 CVE-2025-68461

Roundcube Webmail could be made to run arbitrary code via cross-site scripting.. ========================================================================== Ubuntu Security Notice USN-8097-1 March 16, 2026 roundcube vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Roundcube Webmail could be made to run arbitrary code via cross-site scripting. Software Description: - roundcube: skinnable AJAX based webmail solution for IMAP servers - metapack Details: It was discovered that Roundcube Webmail did not properly sanitize the animate tag within SVG documents. An attacker could possibly use this issue to cause a cross-site scripting attack. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS roundcube-core 1.6.6+dfsg-2ubuntu0.1+esm2 Available with Ubuntu Pro Ubuntu 22.04 LTS roundcube-core 1.5.0+dfsg.1-2ubuntu0.1~esm5 Available with Ubuntu Pro Ubuntu 20.04 LTS roundcube-core 1.4.3+dfsg.1-1ubuntu0.1~esm6 Available with Ubuntu Pro roundcube-plugins 1.4.3+dfsg.1-1ubuntu0.1~esm6 Available with Ubuntu Pro Ubuntu 18.04 LTS roundcube-core 1.3.6+dfsg.1-1ubuntu0.1~esm6 Available with Ubuntu Pro roundcube-plugins 1.3.6+dfsg.1-1ubuntu0.1~esm6 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8097-1 CVE-2025-68461 . Roundcube Webmail security update for Ubuntu releases addresses cross-site scripting risks. Upgrade to mitigate risks..Roundcube Webmail, Ubuntu security, cross site scripting. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 16, 2026 Important Ubuntu
197

Debian 11 Roundcube Information Disclosure Update DLA-4480-1 CVE-2026-25916

Vulnerabilities were discovered in Roundcube, a skinnable AJAX based webmail solution for IMAP servers, which might lead to information disclosure or privilege escalation. CVE-2026-25916 NULL CATHEDRAL discovered that the HTML sanitizer doesn't treat SVG. ------------------------------------------------------------------------- Debian LTS Advisory DLA-4480-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Guilhem Moulin February 17, 2026 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : roundcube Version : 1.4.15+dfsg.1-1+deb11u7 CVE ID : CVE-2026-25916 CVE-2026-26079 Debian Bug : 1127447 Vulnerabilities were discovered in Roundcube, a skinnable AJAX based webmail solution for IMAP servers, which might lead to information disclosure or privilege escalation. CVE-2026-25916 NULL CATHEDRAL discovered that the HTML sanitizer doesn't treat SVG ` ` as an image source. This allows attackers to bypass remote image blocking to track email open action or potentially bypass access control. CVE-2026-26079 CERT Polska discovered that CSS code in text/html emails were insufficiently sanitized, allowing an attacker to inject malicious stylesheet rules. For Debian 11 bullseye, these problems have been fixed in version 1.4.15+dfsg.1-1+deb11u7. We recommend that you upgrade your roundcube packages. For the detailed security status of roundcube please refer to its security tracker page at: https://security-tracker.debian.org/tracker/roundcube Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Roundcube security patch for Debian LTS resolves information disclosure and privilege escalation issues. Upgrade now!. Debian Security Advisories, Roundcube IMAP Security, Privilege Escalation Fixes. .Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 17, 2026 Important Debian LTS
87

Debian Roundcube Important CSS Injection Threat DSA-6137-1 CVE-2026-25916

CERT Polska and nullcathedral discovered that roundcube, a skinnable AJAX based webmail solution for IMAP servers, did not correctly process and sanitize requests. This would allow an attacker to perform CSS injection attacks, or leak sensitive information. For the oldstable distribution (bookworm), these problems have been fixed. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6137-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Sebastien Delafond February 17, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : roundcube CVE ID : CVE-2026-25916 CVE-2026-26079 Debian Bug : 1127447 CERT Polska and nullcathedral discovered that roundcube, a skinnable AJAX based webmail solution for IMAP servers, did not correctly process and sanitize requests. This would allow an attacker to perform CSS injection attacks, or leak sensitive information. For the oldstable distribution (bookworm), these problems have been fixed in version 1.6.5+dfsg-1+deb12u7. For the stable distribution (trixie), these problems have been fixed in version 1.6.13+dfsg-0+deb13u1. We recommend that you upgrade your roundcube packages. For the detailed security status of roundcube please refer to its security tracker page at: https://security-tracker.debian.org/tracker/roundcube Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Roundcube's security advisory DSA-6137-1 addresses important CSS injection risks for Debian. Upgrade recommended.. Roundcube Security Advisory, Debian Update, CSS Injection Attack, Information Leak, Webmail Vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 17, 2026 Important Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200