Mmastodon TechnologyCybersecurity first seen 5 h ago, last 5 h ago, peak #4
Roundcube Webmail SQL Injection Flaw Actively Exploited
Original: Roundcube Webmail SQL Injection Vulnerability CVE-2026-48842 Under Active Exploitation Roundcube Webmail high-severity S
A high-severity SQL injection vulnerability in Roundcube Webmail, tracked as CVE-2026-48842, is under active exploitation. The flaw resides in the virtuser_query plugin and allows unauthenticated attackers to compromise servers running the popular open-source webmail software. Security administrators are being urged to patch affected installations immediately and check systems for signs of compromise.
Why now: Actively exploited vulnerabilities in widely used email software prompt urgent patching and discussion among security professionals.
RoundcubeCVE-2026-48842virtuser_query plugin
Evidence
- Roundcube Webmail SQL Injection Vulnerability CVE-2026-48842 Under Active Exploitation Roundcube Webmail high-severity SQL injection vulnerability (CVE-2026-48842) in its virtuser_query plugin is being actively exploited, allowing unauthenticated attackers to compromise… · beyondmachines1@infosec.exchange · 2
API: https://socialmediatrends-api.osmike.com/v1/trends/993549