vulnerability
Roundcube Webmail Vulnerability in Attackers’ Crosshairs
HighCVSS 8.8KEVEPSS 99%
Summary
A high-severity SQL injection vulnerability (CVE-2026-48842) in the Roundcube webmail client’s virtuser_query plugin is being actively exploited by threat actors. Canadian authorities have confirmed active exploitation, and over 500,000 Roundcube servers are believed to be vulnerable.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data