Roundcube has issued security updates for its webmail software, releasing versions 1.6.17 and 1.7.2 to address multiple vulnerabilities. The advisory highlights problems affecting earlier releases, with cross-site scripting and server-side request forgery among the issues referenced.

The update was noted in a post to the oss-sec mailing list by Valtteri Vuorikoski on July 22, pointing back to Roundcube’s July 5 release announcement. Based on the notice, systems running versions prior to 1.6.17 and 1.7.2 may remain exposed to several security weaknesses if they have not yet been updated.

For organizations and administrators that rely on Roundcube as a webmail frontend, the release underscores the importance of keeping internet-facing communication tools fully patched. Vulnerabilities such as XSS can affect user sessions and browser-based activity, while SSRF-related issues can create additional risk depending on deployment and configuration.

The published notice does not change the basic guidance: users of affected Roundcube versions should review the security release and move to the fixed versions as soon as practical. The update is part of ongoing maintenance for the platform and is aimed at reducing exposure across older installations.