hacker-news · Crawled Sep 25, 2026

Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

1 Malware 3 CVEs
Read original article ↗

AI Summary

A pre-authentication SQL injection vulnerability in Roundcube Webmail, tracked as CVE-2026-48842, is being actively exploited in the wild. The flaw exists in the virtuser_query plugin of versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1, allowing unauthenticated attackers to inject arbitrary SQL and potentially access mail account credentials and stored messages. The Canadian Centre for Cyber Security and SentinelOne have confirmed active exploitation, though specific threat actor details remain limited. Patches were released in May 2026, but over 500,000 Roundcube instances remain internet-exposed, with at least 10 identified as vulnerable as of late September 2026.

AI-extracted · verify before operational use

Extracted Entities 4 found

MITRE ATT&CK TTPs 13 techniques