Security updates 1.6.11 and 1.5.10 released
Free and open source webmail software for the masses, written in PHP
We just published security updates to the 1.6 and 1.5 LTS versions of Roundcube Webmail. They both contain a fix for recently reported security vulnerability.
Security fixes
- Fix Post-Auth RCE via PHP Object Deserialization reported by firs0v.
We strongly recommend to update all productive installations of Roundcube 1.6.x and 1.5.x with this new versions.