CVE detail
CVE-2026-74997
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder replacement values. This issue only affects Roundcube instances using the markasjunk plugin with its cmd_learn driver.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 19.5 · diversity 10.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 6
- within the 30d window
- Peak daily
- 6
- highest bucket
Evidence
Source links by recency
6 source links · newest first
No excerpt available.
Vendor Advisoryroundcube.netAug 17, 2026, 1:16 PMNo excerpt available.
Exploitgithub.comAug 17, 2026, 1:16 PMNo excerpt available.
Exploitgithub.comAug 17, 2026, 1:16 PM- https://github.com/roundcube/roundcubemail/commit/b8f90e28a46d42e79a69568cba897f8f4223d9cdgithub.com
No excerpt available.
Exploitgithub.comAug 17, 2026, 1:16 PM - https://github.com/roundcube/roundcubemail/commit/495d211638f222336b20f4744545c53712426c2agithub.com
No excerpt available.
Exploitgithub.comAug 17, 2026, 1:16 PM - https://github.com/roundcube/roundcubemail/commit/14044f843cfacbe78b042f659e379d6b4497aa7cgithub.com
No excerpt available.
Exploitgithub.comAug 17, 2026, 1:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-71858CVSS 5.4 · Medium
Notepad++ is a free and open-source source code editor. Prior to 8.9.7, macros loaded from an attacker-controlled shortcuts.xml bypass the HMAC validation applied to UserDefinedCo…
- CVE-2026-71472CVSS 9.1 · Critical
A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authenticated attacker, such as a hub administrator or a Search Custom Resource (CR) editor, to inject malici…
- CVE-2026-68519CVSS 7.1 · High
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, GlancesActions.run() in glances/actions.py ignores --disable-config-exec for on-alert action comma…
- CVE-2026-62982CVSS 8.8 · High
Glances is an open-source system cross-platform monitoring tool. From 4.5.2 until 4.5.6, _sanitize_mustache_dict() in glances/actions.py skips nested list and dictionary strings s…
- CVE-2026-68518CVSS 8.8 · High
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, _sanitize_mustache_dict() in glances/actions.py sanitizes individual Mustache values before chevro…
- CVE-2026-75056CVSS 7.8 · High
In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible