Roundcube Webmail SQL Injection Vulnerability Exploited in the Wild

A critical security issue affecting Roundcube Webmail is now being exploited in the wild, prompting administrators to update exposed installations urgently. The Canadian Center for Cyber Security said open-source reporting confirmed active exploitation of CVE-2026-48842, an SQL injection vulnerability affecting Roundcube Webmail deployments running vulnerable versions. Roundcube published security advisories on May 24, 2026, addressing […]

This article has been indexed from Cyber Security News

Read the original article: