Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild.

The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.

The issue stems from a preg_replace() backslash

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Show HN: I RL-trained an agent that trains models with RL (for –$1.3k)

Show HN: I RL-trained an agent that trains models with RL (for –$1.3k) Source: Hacker News

Show HN: HN Hall of Fame – browse 3,100 legendary Hacker News links

Show HN: HN Hall of Fame – browse 3,100 legendary Hacker News links Source: Hacker News

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git Security researchers at depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched six