Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 464
Alerts This Week
Warning Icon 1 464

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":2,"type":"x","order":2,"pct":66.67,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":33.33,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 66 articles for you...
202

openSUSE Roundcubemail Moderate XSS Info Leak Advisory 2024-0328-1

An update that fixes three vulnerabilities is now available.. openSUSE Security Update: Security update for roundcubemail ______________________________________________________________________________ Announcement ID: openSUSE-SU-2024:0328-1 Rating: moderate References: #1228900 #1228901 Cross-References: CVE-2024-42008 CVE-2024-42009 CVE-2024-42010 Affected Products: openSUSE Backports SLE-15-SP6 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for roundcubemail fixes the following issues: Update to 1.6.8 This is a security update to the stable version 1.6 of Roundcube Webmail. It provides fixes to recently reported security vulnerabilities: * Fix XSS vulnerability in post-processing of sanitized HTML content [CVE-2024-42009] * Fix XSS vulnerability in serving of attachments other than HTML or SVG [CVE-2024-42008] * Fix information leak (access to remote content) via insufficient CSS filtering [CVE-2024-42010] CHANGELOG * Managesieve: Protect special scripts in managesieve_kolab_master mode * Fix newmail_notifier notification focus in Chrome (#9467) * Fix fatal error when parsing some TNEF attachments (#9462) * Fix double scrollbar when composing a mail with many plain text lines (#7760) * Fix decoding mail parts with multiple base64-encoded text blocks (#9290) * Fix bug where some messages could get malformed in an import from a MBOX file (#9510) * Fix invalid line break characters in multi-line text in Sieve scripts (#9543) * Fix bug where "with attachment" filter could fail on some fts engines (#9514) * Fix bug where an unhandled exception was caused by an invalid image attachment (#9475) * Fix bug where a long subject title could not be displayed in some cases(#9416) * Fix infinite loop when parsing malformed Sieve script (#9562) * Fix bug where imap_conn_option's 'socket' was ignored (#9566) * Fix XSS vulnerability in post-processing of sanitized HTML content [CVE-2024-42009] * Fix XSS vulnerability in serving of attachments other than HTML or SVG [CVE-2024-42008] * Fix information leak (access to remote content) via insufficient CSS filtering [CVE-2024-42010] Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP6: zypper in -t patch openSUSE-2024-328=1 Package List: - openSUSE Backports SLE-15-SP6 (noarch): roundcubemail-1.6.8-bp156.2.3.1 References: https://www.suse.com/security/cve/CVE-2024-42008.html https://www.suse.com/security/cve/CVE-2024-42009.html https://www.suse.com/security/cve/CVE-2024-42010.html https://bugzilla.suse.com/1228900 https://bugzilla.suse.com/1228901 . Update for openSUSE roundcubemail resolves security issues, including XSS and information leaks with moderate severity.. openSUSE security, roundcubemail update, moderate security issues, webmail vulnerabilities. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jun 12, 2026 moderate OpenSUSE
202

openSUSE Roundcubemail Important XSS SQL Injection Fix Advisory 2026-0183-1

An update that fixes 8 vulnerabilities is now available.. openSUSE Security Update: Security update for roundcubemail ______________________________________________________________________________ Announcement ID: openSUSE-SU-2026:0183-1 Rating: important References: #1266329 #1266331 #1266332 #1266333 #1266334 #1266335 #1266336 #1266337 Cross-References: CVE-2026-48842 CVE-2026-48843 CVE-2026-48844 CVE-2026-48845 CVE-2026-48846 CVE-2026-48847 CVE-2026-48848 CVE-2026-48849 Affected Products: openSUSE Backports SLE-15-SP6 openSUSE Backports SLE-15-SP7 ______________________________________________________________________________ An update that fixes 8 vulnerabilities is now available. Description: This update for roundcubemail fixes the following issues: Update to 1.6.16 - Fix potential too long value in IMAP ID command (#10136) - CVE-2026-48849: Fix stored XSS/HTML/CSS injection in subject field of the draft restore dialog [boo#1266337] - CVE-2026-48848: Fix CSS injection bypass in HTML sanitizer via SVG [boo#1266336] - CVE-2026-48842: Fix pre-auth SQL injection in virtuser_query plugin via preg_replace backslash escape bypass [boo#1266329] - CVE-2026-48843: Fix SSRF bypass via specific local address URLs [boo#1266331] - CVE-2026-48846: Fix bypass of remote image blocking via CSS var() [boo#1266334] - CVE-2026-48845: Fix local/private URL fetch bypass when remote resources were not allowed [boo#1266333] - CVE-2026-48847: Fix pre-auth arbitrary file delete via redis/memcache session poisoning bypass [boo#1266335] - CVE-2026-48844: Fix code injection vulnerability - remove support for code evaluation in LDAP autovalues option [boo#1266332] Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP7: zypper in -t patch openSUSE-2026-183=1 - openSUSE Backports SLE-15-SP6: zypper in -t patch openSUSE-2026-183=1 Package List: - openSUSE Backports SLE-15-SP7 (noarch): roundcubemail-1.6.16-bp157.2.12.1 - openSUSE Backports SLE-15-SP6 (noarch): roundcubemail-1.6.16-bp156.2.18.1 References: https://www.suse.com/security/cve/CVE-2026-48842.html https://www.suse.com/security/cve/CVE-2026-48843.html https://www.suse.com/security/cve/CVE-2026-48844.html https://www.suse.com/security/cve/CVE-2026-48845.html https://www.suse.com/security/cve/CVE-2026-48846.html https://www.suse.com/security/cve/CVE-2026-48847.html https://www.suse.com/security/cve/CVE-2026-48848.html https://www.suse.com/security/cve/CVE-2026-48849.html https://bugzilla.suse.com/1266329 https://bugzilla.suse.com/1266331 https://bugzilla.suse.com/1266332 https://bugzilla.suse.com/1266333 https://bugzilla.suse.com/1266334 https://bugzilla.suse.com/1266335 https://bugzilla.suse.com/1266336 https://bugzilla.suse.com/1266337 . OpenSUSE delivers security updates addressing 8 vulnerabilities in RoundcubeMail ensuring protection against critical risks.. openSUSE updates, RoundcubeMail vulnerabilities, SQL injection, security fixes. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 11, 2026 Important OpenSUSE
203

Mageia 9 RoundCube Webmail Critical Security Issues CVE-2026-48849

Security update. Publication date: 11 Jun 2026 URL: https://advisories.mageia.org/MGASA-2026-0194.html Type: security Affected Mageia releases: 9 CVE: CVE-2026-48842, CVE-2026-48843, CVE-2026-48844, CVE-2026-48845, CVE-2026-48846, CVE-2026-48847, CVE-2026-48848, CVE-2026-48849 Description: Multiple security vulnerabilities were discovered in RoundCube Webmail, which could result in cross-site scripting, SQL injection, SSRF bypass, information disclosure, denial of service or code injection. References: - https://bugs.mageia.org/show_bug.cgi?id=35599 - https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1 - https://lists.debian.org/debian-security-announce/2026/msg00212.html - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./message/HYFEOBDMYY7JRKWNFYSC7KT2TT2XXNBE/ - https://www.openwall.com/lists/oss-security/2026/06/03/17 - https://www.cve.org/CVERecord?id=CVE-2026-48842 - https://www.cve.org/CVERecord?id=CVE-2026-48843 - https://www.cve.org/CVERecord?id=CVE-2026-48844 - https://www.cve.org/CVERecord?id=CVE-2026-48845 - https://www.cve.org/CVERecord?id=CVE-2026-48846 - https://www.cve.org/CVERecord?id=CVE-2026-48847 - https://www.cve.org/CVERecord?id=CVE-2026-48848 - https://www.cve.org/CVERecord?id=CVE-2026-48849 SRPMS: - 9/core/roundcubemail-1.6.16-1.mga9 . Update alerts for Mageia 9 addressing multiple critical security issues in RoundCube Webmail applications.. Mageia Security Update, RoundCube Webmail, Cross-Site Scripting, SQL Injection, Denial of Service. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 10, 2026 Critical Mageia
89

Fedora 43 Roundcube Webmail Important XSS SQL Issues 2026-07ee097ffe

Release 1.6.16 Fix potential too long value in IMAP ID command (#10136) Security: Fix stored XSS/HTML/CSS injection in subject field of the draft restore dialog Security: Fix CSS injection bypass in HTML sanitizer via SVG

Calendar%202 Jun 04, 2026 Important Fedora
89

Fedora 43 Roundcubemail 1.6.16 Key Fix for XSS and SQL Injection Issues

Release 1.6.16 Fix potential too long value in IMAP ID command (#10136) Security: Fix stored XSS/HTML/CSS injection in subject field of the draft restore dialog Security: Fix CSS injection bypass in HTML sanitizer via SVG

Calendar%202 Jun 03, 2026 Important Fedora
89

Fedora 44 RoundcubeMail Critical SQL Injection XSS Issues 2026-2b956d89d3

Release 1.7.1 Enigma: Support automatic public key lookup (import) using HKP v1 protocol (#5314) Managesieve: Fix error when a mail message contains duplicate List-Id header (#10186). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-2b956d89d3 2026-06-03 00:50:32.709746+00:00 -------------------------------------------------------------------------------- Name : roundcubemail Product : Fedora 44 Version : 1.7.1 Release : 1.fc44 URL : http://www.roundcube.net Summary : Round Cube Webmail is a browser-based multilingual IMAP client Description : RoundCube Webmail is a browser-based multilingual IMAP client with an application-like user interface. It provides full functionality you expect from an e-mail client, including MIME support, address book, folder manipulation, message searching and spell checking. RoundCube Webmail is written in PHP and requires a database: MySQL, PostgreSQL and SQLite are known to work. The user interface is fully skinnable using XHTML and CSS 2. -------------------------------------------------------------------------------- Update Information: Release 1.7.1 Enigma: Support automatic public key lookup (import) using HKP v1 protocol (#5314) Managesieve: Fix error when a mail message contains duplicate List-Id header (#10186) Clarified Elastic installation instructions (#10163) Added HTMLFormElement.requestSubmit() polyfill for older browsers (#10179) Fix so "has:attachment" search uses $HasAttachment/$HasNoAttachment keywords (#10168) Fix potential too long value in IMAP ID command (#10136) Fix redis/memcache disconnection in rcube::sleep() (#10127) Fix so static resources, e.g. skin_logo can be put inside the public_html directory (#10160) Fix so REQUEST_URI is used as a fallback if PATH_INFO is not set in static.php (#10181) Fix assets_path feature and remove dependency on PATH_INFO (#10185) Fix MySQL upgrade on MySQL < 8.0 and MariaDB <10.5.3 (#10188) Security: Fix stored XSS/HTML/CSS injection in subject field of the draft restore dialog Security: Fix CSS injection bypass in HTML sanitizer via SVG Security: Fix pre-auth SQL injection in virtuser_query plugin via preg_replace backslash escape bypass Security: Fix SSRF bypass via specific local address URLs Security: Fix bypass of remote image blocking via CSS var() Security: Fix local/private URL fetch bypass when remote resources were not allowed Security: Fix pre-auth arbitrary file delete via redis/memcache session poisoning bypass Security: Fix code injection vulnerability - remove support for code evaluation in LDAP autovalues option -------------------------------------------------------------------------------- ChangeLog: * Mon May 25 2026 Remi Collet - 1.7.1-1 - update to 1.7.1 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2481615 - CVE-2026-48842 roundcubemail: pre-auth SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2481615 [ 2 ] Bug #2481617 - CVE-2026-48844 roundcubemail: code injection via insecure LDAP autovalues option [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2481617 [ 3 ] Bug #2481619 - CVE-2026-48843 roundcubemail: information disclosure and Server-Side Request Forgery via insufficient CSS sanitization [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2481619 [ 4 ] Bug #2481622 - CVE-2026-48845 roundcubemail: privilege escalation via remote image blocking bypass [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2481622 [ 5 ] Bug #2481624 - CVE-2026-48848 roundcubemail: CSS injection via an SVG document that has an animate element with the attributeName attribute [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2481624 [ 6 ] Bug #2481626 - CVE-2026-48847 roundcubemail: arbitrary file deletion viaredis/memcache session poisoning bypass [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2481626 [ 7 ] Bug #2481628 - CVE-2026-48846 roundcubemail: remote image blocking feature can be bypassed via a crafted CSS var() value in an e-mail message [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2481628 [ 8 ] Bug #2481629 - CVE-2026-48849 roundcubemail: XSS via unsanitized subject field in the draft restored value [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2481629 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-2b956d89d3' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Multiple security fixes for roundcubemail 1.7.1 in Fedora 44 addressing XSS and SQL injection issues.. Roundcube Mail Security Update, Fedora 44, SQL Injection Issues, XSS Fixes, Webmail Vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 03, 2026 Critical Fedora
89

Fedora 44 Roundcubemail Critical SQL Injection XSS Vuln 2026-2b956d89d3

Release 1.7.1 Enigma: Support automatic public key lookup (import) using HKP v1 protocol (#5314) Managesieve: Fix error when a mail message contains duplicate List-Id header (#10186). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-2b956d89d3 2026-06-03 00:50:32.709746+00:00 -------------------------------------------------------------------------------- Name : roundcubemail Product : Fedora 44 Version : 1.7.1 Release : 1.fc44 URL : http://www.roundcube.net Summary : Round Cube Webmail is a browser-based multilingual IMAP client Description : RoundCube Webmail is a browser-based multilingual IMAP client with an application-like user interface. It provides full functionality you expect from an e-mail client, including MIME support, address book, folder manipulation, message searching and spell checking. RoundCube Webmail is written in PHP and requires a database: MySQL, PostgreSQL and SQLite are known to work. The user interface is fully skinnable using XHTML and CSS 2. -------------------------------------------------------------------------------- Update Information: Release 1.7.1 Enigma: Support automatic public key lookup (import) using HKP v1 protocol (#5314) Managesieve: Fix error when a mail message contains duplicate List-Id header (#10186) Clarified Elastic installation instructions (#10163) Added HTMLFormElement.requestSubmit() polyfill for older browsers (#10179) Fix so "has:attachment" search uses $HasAttachment/$HasNoAttachment keywords (#10168) Fix potential too long value in IMAP ID command (#10136) Fix redis/memcache disconnection in rcube::sleep() (#10127) Fix so static resources, e.g. skin_logo can be put inside the public_html directory (#10160) Fix so REQUEST_URI is used as a fallback if PATH_INFO is not set in static.php (#10181) Fix assets_path feature and remove dependency on PATH_INFO (#10185) Fix MySQL upgrade on MySQL < 8.0 and MariaDB <10.5.3 (#10188) Security: Fix stored XSS/HTML/CSS injection in subject field of the draft restore dialog Security: Fix CSS injection bypass in HTML sanitizer via SVG Security: Fix pre-auth SQL injection in virtuser_query plugin via preg_replace backslash escape bypass Security: Fix SSRF bypass via specific local address URLs Security: Fix bypass of remote image blocking via CSS var() Security: Fix local/private URL fetch bypass when remote resources were not allowed Security: Fix pre-auth arbitrary file delete via redis/memcache session poisoning bypass Security: Fix code injection vulnerability - remove support for code evaluation in LDAP autovalues option -------------------------------------------------------------------------------- ChangeLog: * Mon May 25 2026 Remi Collet - 1.7.1-1 - update to 1.7.1 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2481615 - CVE-2026-48842 roundcubemail: pre-auth SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2481615 [ 2 ] Bug #2481617 - CVE-2026-48844 roundcubemail: code injection via insecure LDAP autovalues option [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2481617 [ 3 ] Bug #2481619 - CVE-2026-48843 roundcubemail: information disclosure and Server-Side Request Forgery via insufficient CSS sanitization [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2481619 [ 4 ] Bug #2481622 - CVE-2026-48845 roundcubemail: privilege escalation via remote image blocking bypass [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2481622 [ 5 ] Bug #2481624 - CVE-2026-48848 roundcubemail: CSS injection via an SVG document that has an animate element with the attributeName attribute [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2481624 [ 6 ] Bug #2481626 - CVE-2026-48847 roundcubemail: arbitrary file deletion viaredis/memcache session poisoning bypass [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2481626 [ 7 ] Bug #2481628 - CVE-2026-48846 roundcubemail: remote image blocking feature can be bypassed via a crafted CSS var() value in an e-mail message [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2481628 [ 8 ] Bug #2481629 - CVE-2026-48849 roundcubemail: XSS via unsanitized subject field in the draft restored value [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2481629 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-2b956d89d3' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Update for Fedora 44 on Roundcube fixes critical issues including SQL injection and XSS vulnerabilities.. Fedora updates, Roundcube IMAP client, security fixes, XSS vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 02, 2026 Critical Fedora
202

openSUSE Leap 16.0 Roundcube Important SQL Injection Fixes 2026-20852-1

An update that solves 8 vulnerabilities and has 8 bug fixes can now be installed.. openSUSE security update: security update for roundcubemail ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20852-1 Rating: important References: * bsc#1266329 * bsc#1266331 * bsc#1266332 * bsc#1266333 * bsc#1266334 * bsc#1266335 * bsc#1266336 * bsc#1266337 Cross-References: * CVE-2026-48842 * CVE-2026-48843 * CVE-2026-48844 * CVE-2026-48845 * CVE-2026-48846 * CVE-2026-48847 * CVE-2026-48848 * CVE-2026-48849 Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 8 vulnerabilities and has 8 bug fixes can now be installed. Description: This update for roundcubemail fixes the following issues: Changes in roundcubemail: - update to 1.6.16 + Fix potential too long value in IMAP ID command (#10136) + Security: Fix stored XSS/HTML/CSS injection in subject field of the draft restore dialog [CVE-2026-48849] [bsc#1266337] + Security: Fix CSS injection bypass in HTML sanitizer via SVG 'animate attributeName="style"' [CVE-2026-48848] [bsc#1266336] + Security: Fix pre-auth SQL injection in virtuser_query plugin via preg_replace backslash escape bypass [CVE-2026-48842] [bsc#1266329] + Security: Fix SSRF bypass via specific local address URLs [CVE-2026-48843] [bsc#1266331] + Security: Fix bypass of remote image blocking via CSS var() [CVE-2026-48846] [bsc#1266334] + Security: Fix local/private URL fetch bypass when remote resources were not allowed [CVE-2026-48845] [bsc#1266333] + Security: Fix pre-auth arbitrary file delete via redis/memcache session poisoning bypass [CVE-2026-48847] [bsc#1266335] + Security: Fix code injection vulnerability - remove support for code evaluation in LDAP autovalues option [CVE-2026-48844] [bsc#1266332] Patch instructions: To install this openSUSE security update use the suse recommended installation methods likeYaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-packagehub-282=1 Package List: - openSUSE Leap 16.0: roundcubemail-1.6.16-bp160.1.1 References: * https://www.suse.com/security/cve/CVE-2026-48842.html * https://www.suse.com/security/cve/CVE-2026-48843.html * https://www.suse.com/security/cve/CVE-2026-48844.html * https://www.suse.com/security/cve/CVE-2026-48845.html * https://www.suse.com/security/cve/CVE-2026-48846.html * https://www.suse.com/security/cve/CVE-2026-48847.html * https://www.suse.com/security/cve/CVE-2026-48848.html * https://www.suse.com/security/cve/CVE-2026-48849.html . An essential update for openSUSE fixes multiple vulnerabilities in roundcubemail, improving system security and stability.. openSUSE security, roundcubemail update, security issues, important vulnerabilities, software fixes. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 01, 2026 Important OpenSUSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":2,"type":"x","order":2,"pct":66.67,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":33.33,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200