Roundcube shipped eleven security fixes across its current and LTS branches, including an IMAP command injection and a conditional code execution flaw. The notes name no CVE identifiers, so version-matching scanners stay quiet, and cPanel has historically taken five to nine days to follow.