A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security.
Attackers are exploiting CVE-2026-48842 against unpatched Roundcube servers months after a fix was released, raising urgency ...
Roundcube shipped emergency security updates on August 9, 2026, patching eleven distinct vulnerabilities across both its LTS and current stable branches simultaneously — a batch that includes a ...
The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query ...
Attackers are currently exploiting a security vulnerability in Roundcube webmail. However, the prerequisites must be met.
Threat actors have been exploiting a high-severity vulnerability in Roundcube, the popular open source webmail client, the Canadian Centre for Cyber Security warns. Tracked as CVE-2026-48842 (CVSS ...
Up first, if you’re running a Roundcube install prior to 1.5.10 or 1.6.11, it’s time to update. We have an authenticated Remote Code Execution (RCE) in the Roundcube Webmail client. And while that’s ...
The US IT security authority CISA warns of attacks on the open-source software Roundcube Webmail. It concerns a critical and a high-risk vulnerability that criminals are now apparently targeting. The ...
CISA warns that a Roundcube email server vulnerability patched in September is now actively exploited in cross-site scripting (XSS) attacks. The security flaw (CVE-2023-43770) is a persistent ...