Security
Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild
The Hacker News·September 25, 2026·1 min read
The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability, CVE-2026-48842 (CVSS 8.1), is being actively exploited in the wild. The pre-authentication SQL injection in the virtuser_query plugin affects versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1, stemming from a preg_replace() backslash issue.
Read at The Hacker NewsDaily crypto arcade
Read the news, then play it.
Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.
