#10
SecurityWeek
general
September 25, 2026 at 06:57 UTC
Roundcube Webmail Vulnerability in Attackers’ Crosshairs
By Ionut Arghire
AI Summary
CVE-2026-48842, an unauthenticated SQL injection vulnerability in Roundcube Webmail, is being actively exploited in the wild. Roundcube is widely deployed by governments and organizations globally and has been a repeated target of nation-state actors including APT28, making prompt patching essential for any exposed instance.
Relevance score: 74.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →