CVE-2026-62642

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which may lead to denial of service upon opening an email with a TNEF attachment.


We have discovered 9,391 live websites that are affected by CVE-2026-62642.

Run a Free Instant Scan




Affected Software

Product  RoundCube
Category Web Mail
Vulnerable Domains9,391 live websites (64% of RoundCube install base)
Vulnerable Versions
  • from 1.6 through 1.6.17
  • from 1.7 through 1.7.2
Vulnerable Versions Count19 versions ( 35% of all versions)


Common Weakness Enumeration

CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')



Details

  • Published - Jul 14, 2026
  • Updated - Jul 14, 2026

Website Distribution by Country

Number of websites using CVE-2026-62642
United States1,283 websites



Germany1,463 websites
Spain527 websites
France505 websites
Brazil470 websites
Poland453 websites
Netherlands327 websites
Canada326 websites
Czech Republic274 websites
GB248 websites

Website Distribution by TLD

Number of websites using CVE-2026-62642
.com2,201 websites
.net768 websites
.de667 websites
.com.br446 websites
.org417 websites
.pl367 websites
.nl263 websites
.cz247 websites
.it237 websites
.es209 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-62642

Top websites that are affected by CVE-2026-62642. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.**************.com United States**,***
****.********.net United States**,***
********.******.se Sweden**,***
****.*****.com Canada**,***
*******.**************.de Germany**,***
*******.*********.com **,***
*******.*****.**.uk GB**,***
****.**********.nl Netherlands**,***
*******.*****.hosting Ireland***,***
*******.*****.net Czech Republic***,***
See full domain list

FAQ

CVE-2026-62642 is Loop with Unreachable Exit Condition ('Infinite Loop') in RoundCube
A total of 9,391 websites have been identified as vulnerable to CVE-2026-62642, based on global website indexing conducted by WebTechSurvey.
The RoundCube is affected by the CVE-2026-62642 vulnerability.
RoundCube versions up to 1.7.2 are vulnerable to CVE-2026-62642.
CVE-2026-62642 is resolved in version 1.7.2 of RoundCube.