Users can execute commands on the server by writing e-mails, due to insufficient sanitation of the from field when calling PHP's mail() function (CVE-2016-9920).
Note that only roundcubemail installations that don't have an SMTP server configured for mail delivery are affected.