CVE-2026-75006

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. This issue exists because of insufficient fixes for CVE-2026-35540, CVE-2026-48843 and CVE-2026-62643.


We have discovered 9,367 live websites that are affected by CVE-2026-75006.

Run a Free Instant Scan




Affected Software

Product  RoundCube
Category Web Mail
Vulnerable Domains9,367 live websites (65% of RoundCube install base)
Vulnerable Versions
  • from 1.6 through 1.6.18
  • from 1.7 through 1.7.3
Vulnerable Versions Count21 versions ( 38% of all versions)


Common Weakness Enumeration

CWE-918 Server-Side Request Forgery (SSRF)



Details

  • Published - Aug 17, 2026
  • Updated - Aug 17, 2026

Website Distribution by Country

Number of websites using CVE-2026-75006
United States1,329 websites



Germany1,477 websites
Spain524 websites
France469 websites
Brazil460 websites
Poland447 websites
Netherlands324 websites
Canada313 websites
Czech Republic268 websites
Russia243 websites

Website Distribution by TLD

Number of websites using CVE-2026-75006
.com2,158 websites
.net787 websites
.de681 websites
.com.br433 websites
.org417 websites
.pl357 websites
.nl257 websites
.cz240 websites
.it229 websites
.es209 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-75006

Top websites that are affected by CVE-2026-75006. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.**************.com United States**,***
****.********.net United States**,***
********.******.se Sweden**,***
****.*****.com Canada**,***
*******.**************.de Germany**,***
*******.*********.com United States**,***
*******.*****.**.uk GB**,***
****.**********.nl Netherlands**,***
*******.*****.hosting Ireland***,***
*******.*****.net Czech Republic***,***
See full domain list

FAQ

CVE-2026-75006 is Server-Side Request Forgery (SSRF) in RoundCube
A total of 9,367 websites have been identified as vulnerable to CVE-2026-75006, based on global website indexing conducted by WebTechSurvey.
The RoundCube is affected by the CVE-2026-75006 vulnerability.
RoundCube versions up to 1.7.3 are vulnerable to CVE-2026-75006.
CVE-2026-75006 is resolved in version 1.7.3 of RoundCube.