CVE-2026-74997

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder replacement values. This issue only affects Roundcube instances using the markasjunk plugin with its cmd_learn driver.


We have discovered 9,367 live websites that are affected by CVE-2026-74997.

Run a Free Instant Scan




Affected Software

Product  RoundCube
Category Web Mail
Vulnerable Domains9,367 live websites (65% of RoundCube install base)
Vulnerable Versions
  • from 1.6 through 1.6.18
  • from 1.7 through 1.7.3
Vulnerable Versions Count21 versions ( 38% of all versions)


Common Weakness Enumeration

CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')



Details

  • Published - Aug 17, 2026
  • Updated - Aug 17, 2026

Website Distribution by Country

Number of websites using CVE-2026-74997
United States1,329 websites



Germany1,477 websites
Spain524 websites
France469 websites
Brazil460 websites
Poland447 websites
Netherlands324 websites
Canada313 websites
Czech Republic268 websites
Russia243 websites

Website Distribution by TLD

Number of websites using CVE-2026-74997
.com2,158 websites
.net787 websites
.de681 websites
.com.br433 websites
.org417 websites
.pl357 websites
.nl257 websites
.cz240 websites
.it229 websites
.es209 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-74997

Top websites that are affected by CVE-2026-74997. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.**************.com United States**,***
****.********.net United States**,***
********.******.se Sweden**,***
****.*****.com Canada**,***
*******.**************.de Germany**,***
*******.*********.com United States**,***
*******.*****.**.uk GB**,***
****.**********.nl Netherlands**,***
*******.*****.hosting Ireland***,***
*******.*****.net Czech Republic***,***
See full domain list

FAQ

CVE-2026-74997 is Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in RoundCube
A total of 9,367 websites have been identified as vulnerable to CVE-2026-74997, based on global website indexing conducted by WebTechSurvey.
The RoundCube is affected by the CVE-2026-74997 vulnerability.
RoundCube versions up to 1.7.3 are vulnerable to CVE-2026-74997.
CVE-2026-74997 is resolved in version 1.7.3 of RoundCube.