SécuritéUrgentNon vérifié

Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild. The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1. The issue stems from a preg_replace() backslash

Contenu original affiche; la traduction localisee n'est pas encore disponible.

Ce qui s'est passé

The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild. The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1. The issue stems from a preg_replace() backslash

Pourquoi c'est important

The incident may affect operational continuity, asset safety or trust around Security. Watch for verified scope and remediation.

Entités concernées

Voir les preuves

1 articles · 1 publication d'origine · 1 independantes

  1. The Hacker NewsSource primaire · Confirme · EN · 100%
    Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild ↗

Affirmations

  • Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild Observé

Divergences

Aucune divergence importante détectée dans les preuves disponibles.

Chronologie

  1. Premier signalement

Mouvement de marché suivant l'événement

La réaction du marché n'est pas encore disponible pour cet actif et cette fenêtre.

Explication des scores

Confiance · formule confidence-2.1.0
Fiabilité des sources80
Corroboration indépendante51
Preuve primaire35
Cohérence des affirmations82
Confiance d'extraction82
Qualité de l'attribution90
Impact · formule impact-2.1.0
Ampleur de l'événement96
Pertinence marché74
Importance des entités42
Étendue du marché45
Nouveauté68
Urgence96
Classement · formule rank-1.0.0
Facteur de confiance0.8425
Facteur de fraîcheur0.9995
Bonus d'urgence8
Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild | IntelCap