< Back to all clusters
[TECHNOLOGY] · 2 sources

started · updated

CERT-FR alerts on multiple vulnerabilities in Roundcube webmail and Microsoft Edge browser

The French Computer Emergency Response Team (CERT-FR) published an advisory reporting several security flaws in Roundcube Webmail. Affected versions include 1.5.x before 1.5.14, 1.6.x before 1.6.14 and 1.7.x before 1.7‑rc5. The issues comprise data confidentiality breaches, server‑side request forgery (SSRF), cross‑site scripting (XSS) and cross‑site request forgery (CSRF). The advisory cites CVE‑2026‑35537, CVE‑2026‑35544 and CVE‑2026‑35545 and directs users to the Roundcube security‑updates bulletin for patches.

A separate CERT‑FR notice details multiple vulnerabilities in Microsoft Edge for Android, affecting versions prior to 149.0.4022.105 and 150.0.7871.114. The flaws can compromise data integrity and include an unspecified security issue. The bulletin lists a series of CVE identifiers (e.g., CVE‑2026‑62828, CVE‑2026‑13282‑15116) released in July 2026 and advises applying the vendor‑provided updates.

Entities

CERT-FR · Microsoft Edge · Roundcube

Sources