Vulnerabilities & PatchesEmerging1 src
CVE-2026-74997 - Roundcube Webmail Markasjunk Plugin Remote Code Execution Vulnerability
CVE ID : CVE-2026-74997
Published : Aug. 17, 2026, 12:37 p. m.
• 30 minutes ago
Description : In Roundcube Webmail before 1. 6. 18 and 1. 7. x before 1. 7. 3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder replacement values. This issue only affects Roundcube instances using the markasjunk plugin with its cmd_learn driver.
Severity: 8.8
• HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...