CVE-2026-75000

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking bypass, which in turn may lead to information disclosure or privilege escalation.


We have discovered 9,367 live websites that are affected by CVE-2026-75000.

Run a Free Instant Scan




Affected Software

Product  RoundCube
Category Web Mail
Vulnerable Domains9,367 live websites (65% of RoundCube install base)
Vulnerable Versions
  • from 1.6 through 1.6.18
  • from 1.7 through 1.7.3
Vulnerable Versions Count21 versions ( 38% of all versions)


Common Weakness Enumeration

CWE-669 Incorrect Resource Transfer Between Spheres



Details

  • Published - Aug 17, 2026
  • Updated - Aug 18, 2026

Website Distribution by Country

Number of websites using CVE-2026-75000
United States1,329 websites



Germany1,477 websites
Spain524 websites
France469 websites
Brazil460 websites
Poland447 websites
Netherlands324 websites
Canada313 websites
Czech Republic268 websites
Russia243 websites

Website Distribution by TLD

Number of websites using CVE-2026-75000
.com2,158 websites
.net787 websites
.de681 websites
.com.br433 websites
.org417 websites
.pl357 websites
.nl257 websites
.cz240 websites
.it229 websites
.es209 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-75000

Top websites that are affected by CVE-2026-75000. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.**************.com United States**,***
****.********.net United States**,***
********.******.se Sweden**,***
****.*****.com Canada**,***
*******.**************.de Germany**,***
*******.*********.com United States**,***
*******.*****.**.uk GB**,***
****.**********.nl Netherlands**,***
*******.*****.hosting Ireland***,***
*******.*****.net Czech Republic***,***
See full domain list

FAQ

CVE-2026-75000 is Incorrect Resource Transfer Between Spheres in RoundCube
A total of 9,367 websites have been identified as vulnerable to CVE-2026-75000, based on global website indexing conducted by WebTechSurvey.
The RoundCube is affected by the CVE-2026-75000 vulnerability.
RoundCube versions up to 1.7.3 are vulnerable to CVE-2026-75000.
CVE-2026-75000 is resolved in version 1.7.3 of RoundCube.