High-Severity Roundcube Webmail Vulnerability (CVE-2026-48842) Actively Exploited
A high-severity pre-authentication SQL injection vulnerability (CVE-2026-48842) in Roundcube Webmail, affecting versions 1.6.0 to before 1.6.16 and 1.7.0 to before 1.7.1, is reportedly being actively exploited. Users and administrators are urged to update immediately to prevent unauthenticated attackers from injecting arbitrary SQL statements.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.