A vulnerability described as critical has been identified in Roundcube Webmail up to 1.6.15/1.7.0. Impacted is an unknown function. The manipulation results in incomplete blacklist.

This vulnerability is identified as CVE-2026-9818. The attack can be executed remotely. There is not any exploit available.

Upgrading the affected component is recommended.