Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

The Hacker News - Sep 25, 2026

The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild. The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1. The issue stems from a preg_replace() backslash

Read full article

More News

Still Surge

Let your "surge" of emotions burst forth when reading the news articles acknowledging the beauty and vastness of Science and futuristic Technologies.

NEWSLETTER