Tracked as CVE-2026-48842, the exploited bug is an SQL injection that can be exploited without authentication.
Roundcube Webmail Vulnerability in Attackers’ Crosshairs
About this summary. This is a short, independently written summary of an article first published by SecurityWeek. Cyber Security News did not report or verify the underlying story. Read the original: https://www.securityweek.com/roundcube-webmail-vulnerability-in-attackers-crosshairs/
Source attribution: headline and facts are from SecurityWeek (securityweek.com). Summary method: excerpt of the source description. See our source attribution policy.



