CVE-2026-48842

Pierluigi Paganini September 28, 2026
Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild

Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild, putting unpatched webmail servers at risk of database compromise. A Roundcube Webmail vulnerability, tracked as CVE-2026-48842 (CVSS score of 8.1) and patched four months ago, is now being exploited in the wild. The Canadian Centre for Cyber Security added the warning to its advisory […]