Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild, putting unpatched webmail servers at risk of database compromise. A Roundcube Webmail vulnerability, tracked as CVE-2026-48842 (CVSS score of 8.1) and patched four months ago, is now being exploited in the wild. The Canadian Centre for Cyber Security added the warning to its advisory on September 21, citing open-source reporting and urging administrators to apply the available updates.
Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild
About this summary. This is a short, independently written summary of an article first published by Security Affairs. Cyber Security News did not report or verify the underlying story. Read the original: https://securityaffairs.com/199882/security/roundcube-sql-injection-cve-2026-48842-is-now-being-exploited-in-the-wild.html
Source attribution: headline and facts are from Security Affairs (securityaffairs.com). Summary method: excerpt of the source description. See our source attribution policy.






