Attackers are exploiting CVE-2026-48842 against unpatched Roundcube servers months after a fix was released, raising urgency ...
The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query ...
Roundcube shipped emergency security updates on August 9, 2026, patching eleven distinct vulnerabilities across both its LTS and current stable branches simultaneously — a batch that includes a ...
Attackers are currently exploiting a security vulnerability in Roundcube webmail. However, the prerequisites must be met.
Roundcube is an open-source application for managing email through a Web interface. It runs on Web servers that support the PHP server-side scripting language. Roundcube may be a good choice for your ...
Threat actors have been exploiting a high-severity vulnerability in Roundcube, the popular open source webmail client, the Canadian Centre for Cyber Security warns. Tracked as CVE-2026-48842 (CVSS ...
Threat actors are targeting a critical and high severity vulnerability in Roundcube Webmail, which is widely used in government and higher education, according to security researchers. The ...
A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security.
The threat associated with a critical decade-old remote code execution vulnerability in Roundcube webmail has increased sharply in recent days, with proof-of-concept (PoC) code for the bug becoming ...
Jesus Vigo reviews the steps necessary to add a front-end webmail application using Roundcube that’s hosted on OS X Server. In a previous article, I covered the steps on how to setup and configure the ...
The Winter Vivern APT group has been exploiting a zero-day vulnerability (CVE-2023-5631) in Roundcube webmail servers to spy on email communications of European governmental entities and a think tank, ...
CISA warns that a Roundcube email server vulnerability patched in September is now actively exploited in cross-site scripting (XSS) attacks. The security flaw (CVE-2023-43770) is a persistent ...