Roundcube SQLi (CVE-2026-48842) Exploited A pre-authentication SQL injection vulnerability in Roundcube Webmail is reportedly being exploited in the wild months after patches became available. Tracked as CVE-2026-48842, the flaw affects Roundcube’s virtuser_query plugin and was fixed in versions 1.6.16 and 1.7.1 on May 24, 2026. On September 21, the Canadian Centre for Cyber Security updated its advisory to state that open-source reporting indicated exploitation in the wild.
Roundcube SQLi (CVE-2026-48842) Exploited
About this summary. This is a short, independently written summary of an article first published by SOCRadar. Cyber Security News did not report or verify the underlying story. Read the original: https://socradar.io/blog/roundcube-sqli-cve-2026-48842/
Source attribution: headline and facts are from SOCRadar (socradar.io). Summary method: excerpt of the source description. See our source attribution policy.



