Cybersecurity · September 26, 2026
Canada's national cyber security centre says attackers are actively exploiting a serious flaw in Roundcube Webmail that requires no login at all. Tracked as CVE-2026-48842 with a CVSS score of 8.1, the bug sits in the virtuser_query plugin and lets an unauthenticated attacker inject SQL queries against vulnerable servers. It affects Roundcube 1.6.x builds older than 1.6.16 and 1.7.x builds older than 1.7.1, so administrators should patch without delay.
// source: thehackernews.com ↗