Tag: webmail security
2 articles

Hackers Exploit Roundcube Flaw in Code Injection Attacks
Over 523,000 Roundcube webmail instances are vulnerable to a high-severity flaw, CVE-2026-48842, that's being exploited by hackers to inject malicious code and steal sensitive data. This pre-authenticated SQL injection vulnerability allows attackers to bypass authentication and wreak havoc on your database.

CSS Attacks Break Webmail Defenses to Steal Passwords and Tokens
Researchers have discovered alarming proof-of-concept techniques that allow attackers to exploit styled HTML in emails, breaking through webmail defenses to steal passwords, tokens, and even hijack trusted actions. This vulnerability affects major email services including Outlook, Gmail, and Yahoo Mail, and public proof-of-concept code is readily available.