Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

Cybersecurity · September 26, 2026

Cybersecurity·thehackernews.com

Canada's national cyber security centre says attackers are actively exploiting a serious flaw in Roundcube Webmail that requires no login at all. Tracked as CVE-2026-48842 with a CVSS score of 8.1, the bug sits in the virtuser_query plugin and lets an unauthenticated attacker inject SQL queries against vulnerable servers. It affects Roundcube 1.6.x builds older than 1.6.16 and 1.7.x builds older than 1.7.1, so administrators should patch without delay.

// source: thehackernews.com ↗

← Back to Blog