chiprook
← Security
SecuritySeptember 24, 2026, 20:27

Hackers now exploit critical Roundcube flaw in code injection attacks

Canada's Centre for Cyber Security warns that CVE-2026-48842, a Roundcube Webmail flaw patched in May, is now being actively exploited. The pre-authenticated SQL injection in the virtuser_query plugin lets attackers bypass authentication and steal database data. Over 523,000 Roundcube instances are exposed online.

Hackers now exploit critical Roundcube flaw in code injection attacks
#Roundcube
Read next
Security

DoJ: Uncle Sam bought forensics software from same Russian op supplying FSB

Security

Actively exploited VeloCloud Orchestrator flaw patched only in some versions

Security

Ghost Service Accounts Enable M365 Data Theft in Chile

Security

Russian strikes damage Kyiv data centers, cutting internet for 100,000 households