chiprook
← Security
SecuritySeptember 25, 2026, 13:57

Attackers exploit Roundcube SQL injection CVE-2026-48842

Canada's Centre for Cyber Security warns that threat actors are exploiting CVE-2026-48842 (CVSS 8.1), an unauthenticated SQL injection in Roundcube's virtuser_query plugin. The flaw was fixed in versions 1.6.16 and 1.7.1, but over 500,000 Roundcube servers remain reachable online.

Attackers exploit Roundcube SQL injection CVE-2026-48842
#Roundcube
Read next
Security

Researchers Flagged AliExpress Phishing Domains Before Registration

Security

Fixing Flock: controls needed after misuse patterns emerge

Security

Gartner: 41% of CISOs hit by AI deepfake voice calls in past year

Security

ZoomEye finds 5.1 million hosts exposing VNC port 5900