The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild. The vulnerability in question is CVE-2026-48842 (CVSS…
Roundcube SQLi (CVE-2026-48842) Exploited A pre-authentication SQL injection vulnerability in Roundcube Webmail is reportedly being exploited in the wild months after patches became available…
Serial number: AV26-503 Date: May 25, 2026 Updated: September 21, 2026 On May 24, 2026, Roundcube published security advisories to address vulnerabilities in the following product: Roundcube Webmail…