#3
The Hacker News
general
September 25, 2026 at 10:14 UTC
Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild
By [email protected] (The Hacker News)
AI Summary
CVE-2026-48842 (CVSS 8.1), a pre-authentication SQL injection vulnerability in Roundcube Webmail's virtuser_query plugin, is being actively exploited in the wild according to the Canadian Centre for Cyber Security. The flaw affects versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1, and stems from a preg_replace() backslash handling issue that requires no authentication to exploit. Organizations running Roundcube for email should patch immediately given active exploitation.
Relevance score: 84.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →