#Roundcube
Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
September 26, 2026 at 12:29 PM
🔒 Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being...

https://tinyurl.com/2akqrms6 #CyberSecurity #InfoSec #CrustyTLDR
September 26, 2026 at 10:02 AM
Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild.

The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a…
#hackernews #news
Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild
The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild. The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1. The issue stems from a preg_replace() backslash
thehackernews.com
September 26, 2026 at 9:16 AM
Hackers now exploit critical Roundcube flaw in code injection attacks www.bleepingcomputer.com/news/securit...
Hackers now exploit critical Roundcube flaw in code injection attacks
A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security.
www.bleepingcomputer.com
September 26, 2026 at 8:42 AM
Jetzt updaten: Angreifer nehmen Roundcube-Instanzen unter Feuer. Das Webmail, das an jeder Uni und in jedem Hostingpaket mitlaeuft, weil es ja nur Mail ist und damit harmlos. In dem Postfach liegen halt bloss alle Passwort-Resets eures Lebens.
Attacken auf Roundcube-Webmail beobachtet
www.heise.de
September 26, 2026 at 7:14 AM
Just another Tuesday in IT, with the Canadian Centre for Cyber Security warning that a Roundcube Webmail pre-auth SQL injection bug, CVE-2026-48842, is being actively exploited. Anyone running Roundcube Webmail gets to suffer through this entirely predictable nightmare. Staying s...

Read full story
September 26, 2026 at 7:03 AM
A pre-auth SQL injection bug in Roundcube Webmail is being actively exploited in the wild. Apparently patching database flaws remains an impossible dream.

#PatchYourFlaws #SQLInjection
September 26, 2026 at 7:03 AM
Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild.

Source: thehackernews.com/2026/09/roundcube-pre-auth-sql-injection-flaw.html
Community: whop.com/cybermaster-d5a7

#CyberSecurity #InfoSec
September 26, 2026 at 6:00 AM
Good morning, Czechia: the world’s digital carnival of half-fixed software, leaked credentials, and “critical” flaws you’ll patch after the next committee meeting is still in full swing. Active exploitation of Roundcube, WordPress, SharePoint, and a parade of fresh CVEs means attackers a

READ MORE
September 26, 2026 at 5:59 AM
📦 rackamx/forward_to_muse v1.0.0

One-click toolbar button to forward messages to your Muse agent.

🔗 https://github.com/rackamx/roundcube-forward-to-muse
September 26, 2026 at 5:59 AM
Roundcube-Lücke CVE-2026-48842 wird angegriffen: jetzt updaten

Eine Sicherheitslücke im Webmailer Roundcube, die seit Mai gepatcht ist, wird inzwischen aktiv angegriffen. Wer betroffen ist, was Admins jetzt prüfen sollten und was die DSGVO verlangt.

#News
Roundcube-Lücke CVE-2026-48842 wird angegriffen: jetzt updaten
Eine Sicherheitslücke im Webmailer Roundcube, die seit Mai gepatcht ist, wird inzwischen aktiv angegriffen. Wer betroffen ist, was Admins jetzt prüfen sollten und was die DSGVO verlangt.
dastechno.com
September 26, 2026 at 3:10 AM
🚀 How to Install #Roundcube on Rocky Linux #VPS (5 Minute Quick-Start Guide)

This article explains how to install Roundcube on Rocky Linux VPS.
What is Roundcube?
Roundcube is a free, ...
Continued 👉 #apache #selfhosted #letsencrypt #selfhosting #certbot #phpfpm #mariadb #rockylinux
🚀 How to Install Roundcube on Rocky Linux VPS (5 Minute Quick-Start Guide)
blog.radwebhosting.com
September 26, 2026 at 1:27 AM
Roundcube Webmail 1.7.0 Pre-Authentication SQL Injection https://packetstorm.news/files/232796 #exploit
September 25, 2026 at 11:39 PM
Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

https://thehackernews.com/2026/09/roundcube-pre-auth-sql-injection-flaw.html

#CyberSecurity #InfoSec
September 25, 2026 at 9:00 PM
Han trobat una de les portes del darrera que l’NSA portava anys fent servir, toca tancar-la XD.
September 25, 2026 at 7:35 PM
Unauthenticated SQLi (CVE-2026-48842) in Roundcube's virtuser_query plugin lets attackers steal mail data. Patches were out in May '26. That it's still actively exploited makes me intrigued and worried about patching ...
Roundcube Webmail Vulnerability in Attackers' Crosshairs
Threat actors are actively exploiting a high-severity SQL injection vulnerability (CVE-2026-48842) in Roundcube, a widely used open-source webmail client. The flaw, found in the virtuser_query plugin,
www.securityweek.com
September 25, 2026 at 5:04 PM
🖲️ #Noticia #CiberSeguridad #Cybersecurity #CiberNoticia

Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

Leer Más / Read More...
Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild
Haz clic para acceder al contenido completo.
thehackernews.com
September 25, 2026 at 3:28 PM
Critical Roundcube Flaw Under Active Exploitation in Code Injection Attacks #CodeInjection #RoundcubeWebmail #UserSecurity
Critical Roundcube Flaw Under Active Exploitation in Code Injection Attacks
 A high-severity vulnerability in Roundcube Webmail, patched in May 2026, is now being actively exploited in code injection attacks, according to the Canadian Centre for Cyber Security. The flaw, tracked as CVE-2026-48842, allows unauthenticated attackers to bypass security controls and execute malicious database commands, putting millions of email users at risk.  Roundcube is a browser-based IMAP email client used as the default mail interface by thousands of services and is pre-installed with the widely adopted cPanel web hosting control panel. The vulnerability resides in the virtuser_query plugin, which handles database-driven user lookups and maps users to email addresses. Successful exploitation enables threat actors with no privileges to inject and execute malicious SQL commands, steal data from Roundcube's database, and compromise email systems without requiring any user interaction.  The Roundcube security team addressed this issue in May by releasing patches in versions 1.6.16 and 1.7.1, strongly recommending that administrators update their servers immediately. For those unable to upgrade right away, disabling or removing the virtuser_query plugin eliminates the attack vector and reduces exposure. Despite the availability of fixes, Shadowserver currently tracks over 523,000 Roundcube instances exposed on the Internet, though it remains unclear how many are honeypots or already patched against this flaw.  This is not the first time Roundcube has been targeted by sophisticated threat actors. The Russian Winter Vivern (TA473) group exploited a cross-site scripting zero-day (CVE-2023-5631) against European government entities, while APT28 abused multiple Roundcube flaws to breach Ukrainian government email systems. More recently, in February 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) flagged two other Roundcube vulnerabilities as actively exploited, ordering federal agencies to secure their networks within three weeks. Since May 2022, CISA has tagged 11 Roundcube Webmail vulnerabilities as exploited in the wild, underscoring the platform's persistent appeal to cybercriminals and state-backed hackers.  Organizations relying on Roundcube should prioritize patching to versions 1.6.16 or 1.7.1 without delay, as the window for safe operation has closed. Administrators who cannot upgrade immediately must disable the vulnerable virtuser_query plugin and monitor logs for suspicious database queries or unauthorized access attempts. Given the scale of exposed instances and the history of active exploitation, treating this flaw as a critical priority is essential to prevent data theft, credential harvesting, and broader compromise of email infrastructure.
dlvr.it
September 25, 2026 at 3:05 PM
🤖 CVE-2026-48842 (CVSS 8.1): pre-auth SQL injection in Roundcube Webmail's virtuser_query plugin, actively exploited in the wild per Canadian Centre for Cyber Security. Affects 1.6.x < 1.6.16 and 1.7.x < 1.7.1 — patch…
September 25, 2026 at 2:08 PM
Critical Roundcube Webmail Flaw Actively Exploited in the Wild

The Canadian Centre for Cyber Security has warned that a critical Roundcube Webmail SQL injection vulnerability is being actively exploited in the wild.
Critical Roundcube Webmail Flaw Actively Exploited in the Wild
The Canadian Centre for Cyber Security has warned that a critical Roundcube Webmail SQL injection vulnerability is being actively exploited in the wild.
privacyneedle.com
September 25, 2026 at 1:51 PM
Critical flaws are under active attack across Roundcube, TeamCity, Check Point VPN and WordPress, while SolarWinds and Adobe issue urgent fixes for RCE and other severe bugs. #Roundcube #TeamCity #WordPress
Page Not Found - Cybersecurity News Everyday
www.hendryadrian.com
September 25, 2026 at 12:45 PM
Hackers now exploit critical Roundcube flaw in code injection attacks

A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security. [...]
#hackernews #news
Hackers now exploit critical Roundcube flaw in code injection attacks
A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security. [...]
www.bleepingcomputer.com
September 25, 2026 at 12:09 PM
Roundcube WebmailのSQLインジェクション脆弱性(CVE-2026-48842)により、認証なしで攻撃者が悪用可能。
Roundcube Webmail Vulnerability in Attackers’ Crosshairs
Hackers are exploiting CVE-2026-48842, an unauthenticated SQL injection vulnerability in Roundcube Webmail.
www.securityweek.com
September 25, 2026 at 11:49 AM