Tag: pre auth sql injection
1 article

Roundcube Flaw Exploited in Wild, Warns Canadian Cyber Centre
A critical Roundcube Webmail vulnerability, CVE-2026-48842, is under active exploitation, allowing unauthenticated attackers to inject malicious SQL code and potentially expose sensitive mail account credentials and messages. This flaw affects versions 1.6.x and 1.7.x of Roundcube Webmail, and has been patched in versions 1.6.16 and 1.7.1.