Home / Sep 27, 2026 / Story
0
#10 SecurityWeek general September 25, 2026 at 06:57 UTC

Roundcube Webmail Vulnerability in Attackers’ Crosshairs

By Ionut Arghire

AI Summary

CVE-2026-48842, an unauthenticated SQL injection vulnerability in Roundcube Webmail, is being actively exploited in the wild. Roundcube is widely deployed by governments and organizations globally and has been a repeated target of nation-state actors including APT28, making prompt patching essential for any exposed instance.

Relevance score: 74.0/100

# More from September 27