Monday , September 7 2026

Alert

ALERT
Roundcube Webmail fixes 12 security flaws, including zero-click XSS and SSRF bypass

Roundcube Webmail has given security updates for its 1.6 LTS and 1.7 branches. These updates fix 12 problems that could let users and servers face cross-site scripting, email header issues, data access from other users, remote content tricks, and attacks that misuse server requests. The new versions, Roundcube 1.6.19 and …

Read More »

CVE-2026-62911
Nearly 22,000 Microsoft Exchange Servers are vulnerable to attack

Microsoft Exchange Server

Almost 22,000 Microsoft Exchange servers are online and still vulnerable to a flaw that lets attackers access all user mailboxes. Tracked as CVE-2026-62911 and reported by Orange Tsai from DEVCORE Research Team, this security flaw impacts Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE) software. “Authentication bypass …

Read More »