Cybersecurity
Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild
Roundcube's patched CVE-2026-48842 SQL injection is actively exploited, affecting 1.6.x before 1.6.16 and 1.7.x before 1.7.1.
Summary
The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild. The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.
AI summaries can be wrong sometimes—always verify important details using the source article.
How AI & Automation are usedCoverage Context
More from Cybersecurity
Continue reading recent Cybersecurity coverage
- Windows, Linux, Android File Notification Systems Leak User ActivityContinue reading
- Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend CompromiseContinue reading
- Microsoft: Recent Windows updates cause desktop loading issuesContinue reading
- ‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data ExfiltrationContinue reading
Support HappeningNow
Independent AI-powered news analysis is reader-supported. Your contribution helps cover infrastructure, summaries, and continued platform development.
Support HappeningNow