HackerFeeds

CyberSecurity News

Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

The Hacker News
· September 25, 2026

AI summary

A vulnerability in Roundcube Webmail is being actively exploited, according to a warning from the Canadian Centre for Cyber Security. The issue is a pre-authentication SQL injection flaw in the virtuser_query plugin, identified as CVE-2026-48842 with a CVSS score of 8.1. This vulnerability affects Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1. The problem arises from a preg_replace() backslash issue. The vulnerability has been patched, but exploitation is ongoing.

Vulnerabilities mentioned

Read the full article at The Hacker Newsthehackernews.com/2026/09/roundcube-pre-auth-sql-injection-flaw.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.