tag
Webmail
Critical
SmarterMail Auth Bypass via Password Reset to Pre-Auth RCE (CVE-2025-52691 / WT-2026-0001)
CVE-2025-52691·
SmarterMail (SmarterTools webmail/mail server)
patched
Critical
Roundcube Webmail Post-Auth RCE via PHP Object Deserialization (CVE-2025-49113)
CVE-2025-49113·
Roundcube Webmail
unpatched
Critical
Group-Office TNEF Attachment Handler OS Command Injection (CVE-2026-25512)
CVE-2026-25512·
Group-Office groupware/webmail suite
unpatched