A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security.
Threat actors are actively exploiting a critical SQL injection vulnerability in Roundcube Webmail that can be triggered without authentication.
Roundcube Webmail SQL injection flaw CVE-2026-48842 is actively exploited, urging users to update vulnerable installations.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results