Search
Find merged stories by title or summary.
Attackers Target Unpatched Roundcube Servers With CVE-2026-48842 - TechRepublic
Attackers Target Unpatched Roundcube Servers With CVE-2026-48842 TechRepublic
Roundcube SQLi (CVE-2026-48842) Exploited
Roundcube SQLi (CVE-2026-48842) Exploited A pre-authentication SQL injection vulnerability in Roundcube Webmail is reportedly being exploited in the wild months after patches became available. Tracked as CVE-2026-48842 , the flaw affects Roundcube’s virtuser_query plugin and was fixed in versions 1. 6. 16 and 1. 7. 1 on May 24, 2026. On September 21, the Canadian Centre for Cyber Security updated its advisory to state that open-source reporting indicated exploitation in the wild. What Is CVE-2026-48842? CVE-2026-48842 (CVSS 8.1) is a pre-authentication SQL injection vulnerability (classified as CWE-89) in Roundcube’s virtuser_query plugin, which performs database-backed mappings between usernames and email addresses. Roundcube describes the root cause as a preg_replace() backslash-escape bypass.
Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild
The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild. The vulnerability in question is CVE-2026-48842 (CVSS score: 8. 1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1. 6. x before 1. 6. 16 and 1. 7. x before 1. 7. 1. The issue stems from a preg_replace() backslash
Roundcube Webmail Vulnerability in Attackers’ Crosshairs
Tracked as CVE-2026-48842, the exploited bug is an SQL injection that can be exploited without authentication. The post Roundcube Webmail Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek .
[Previdian] CVE-2026-48842 - Confirmed Exploitation
CVE-2026-48842 Catalog: Previdian Status: Confirmed Exploited: Yes Status Updated: 2026-09-24 09:23 UTC Evidence Sources: 1 First Seen: 2026-09-24 Asserted: 2026-09-24
You've reached the end of current stories for this search.
