chiprook
← Security
SecuritySeptember 28, 2026, 12:50

Roundcube SQL injection CVE-2026-48842 exploited in the wild

Canada's Centre for Cyber Security warned on September 21 that CVE-2026-48842 (CVSS 8.1) in Roundcube is being exploited in the wild. The pre-auth SQL injection in the virtuser_query plugin affects 1.6.x before 1.6.16 and 1.7.x before 1.7.1; the fix shipped on May 24, 2026.

Roundcube SQL injection CVE-2026-48842 exploited in the wild
#Roundcube
Read next
Security

CVE-2026-75682 in Adobe Connect: SQL injection rated 9.9 leads to code execution

Security

CVE-2026-76461: SQL injection in Cisco email gateway grants root

Security

Metabase CVE-2026-72898: unauthenticated SQL injection exposes the data warehouse

Security

Cisco FMC SQL injection CVE-2026-20344: monitoring plan