Roundcube SQLi (CVE-2026-48842) Exploited A pre-authentication SQL injection vulnerability in Roundcube Webmail is reportedly being exploited in the wild months after patches became available. Tracked as CVE-2026-48842, the flaw affects Roundcube’s virtuser_query plugin and was fixed in versions 1.6.16 and 1.7.1 on May 24, 2026. On September 21, the Canadian Centre for Cyber Security updated its advisory to state that open-source reporting indicated exploitation in the wild.

Read the full article at SOCRadar →