Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild | HappeningNow.news

Cybersecurity

Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

Roundcube's patched CVE-2026-48842 SQL injection is actively exploited, affecting 1.6.x before 1.6.16 and 1.7.x before 1.7.1.

Source Summary Published 1h 45m ago Brief Under 1 min brief
Story intelligence
Coverage Single outlet Single-outlet story
Views New Be the first to read
Brief read Under 1 min brief 49 words

Summary

The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild. The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.

Read original at The Hackernews

Coverage Context

Part of SQL coverage 40 tracked stories

More from Cybersecurity

Continue reading recent Cybersecurity coverage

Support HappeningNow

Independent AI-powered news analysis is reader-supported. Your contribution helps cover infrastructure, summaries, and continued platform development.

Support HappeningNow

Report an issue with this page