hacker-news · Crawled Sep 25, 2026
Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild
1 Malware 3 CVEs
Read original article ↗
AI Summary
A pre-authentication SQL injection vulnerability in Roundcube Webmail, tracked as CVE-2026-48842, is being actively exploited in the wild. The flaw exists in the virtuser_query plugin of versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1, allowing unauthenticated attackers to inject arbitrary SQL and potentially access mail account credentials and stored messages. The Canadian Centre for Cyber Security and SentinelOne have confirmed active exploitation, though specific threat actor details remain limited. Patches were released in May 2026, but over 500,000 Roundcube instances remain internet-exposed, with at least 10 identified as vulnerable as of late September 2026.
AI-extracted · verify before operational use
Extracted Entities 4 found
MITRE ATT&CK TTPs 13 techniques
T1027 Obfuscated Files or Information · Defense Evasion T1055 Process Injection · Defense Evasion T1059.001 PowerShell · Execution T1071 Application Layer Protocol · Command And Control T1071.001 Web Protocols · Command And Control T1087.002 Domain Account · Discovery T1090 Proxy · Command And Control T1190 Exploit Public-Facing Application · Initial Access T1085 T1085 T1134 Access Token Manipulation · Defense Evasion T1203 Exploitation for Client Execution · Execution T1218 System Binary Proxy Execution · Defense Evasion T1480 Execution Guardrails · Defense Evasion