Roundcube SQLi (CVE-2026-48842) Exploited
Pre-authentication Roundcube Webmail SQL injection CVE-2026-48842 is reportedly exploited months after patches.
SOCRadar reports that CVE-2026-48842, a pre-authentication SQL injection in Roundcube Webmail, is being exploited in the wild. The activity is described as occurring months after patches became available. The published notice does not identify affected versions, victims, or the scale of exploitation.
- CVE-2026-48842 is a pre-authentication SQL injection in Roundcube Webmail.
- Exploitation is reported in the wild months after patches shipped.
- The notice names no victims, versions, or exploitation volume.
Vulnerabilities mentionedAll →
- CVE-2026-488428.1<1%Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash…published PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-48842 | Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash… |
Roundcube SQLi (CVE-2026-48842) Exploited A pre-authentication SQL injection vulnerability in Roundcube Webmail is reportedly being exploited in the wild months after patches became available. Tracked as CVE-2026-48842 ,
The full text could not be extracted from this site (paywall, bot protection or heavy scripting). Read it at socradar.io.