High 8.1
CVE-2026-48842
Active Exploitation of Pre-Auth SQL Injection Vulnerability CVE-2026-48842 in Roundcube Webmail
Vendor / product: Roundcube Webmail
Event date: 2026-09-25
Public PoC: Yes
First tracked by RiskWire: 2026-09-23
Sources & citations (9)
- Critical NEXT.JS Flaw Enables RCE Attacks Via Weaponized SVG File cybersecuritynews.com · 2026-09-23
- Roundcube Webmail Under Attack: 523,000 Instances Exposed Online esecurityplanet.com · 2026-09-25
- Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild thehackernews.com · 2026-09-25
- Update now! Attacks on Roundcube webmail instances observed heise.de · 2026-09-25
- Roundcube CVE-2026-48842: Active Exploitation Reported for Pre-Authentication SQL Injection in virtuser_query dev.to · 2026-09-25
- CISA Warns of WSO2 Multiple Products Vulnerability Exploited in Attacks cybersecuritynews.com · 2026-09-25
- CISA Flags WSO2 Security Flaw Under Active Exploitation gbhackers.com · 2026-09-25
- WSO2's CVSS 10.0 JWT Bypass Has Been Exploited for 12 Days. The Patch Has Been Out Since April. tech.yahoo.com · 2026-09-25
- CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks bleepingcomputer.com · 2026-09-25
References
See CVE-2026-48842 in context
RiskWire tracks every exploited CVE this week, cross-referenced against CISA KEV with federal remediation deadlines. Filtered to your vendor stack.
Book a 20-min demo →