Attackers Target Unpatched Roundcube Servers With CVE-2026-48842
Months after a flaw was patched, threat actors are now betting that not everyone got the patch. Image: Mariia Berezovsky/Unsplash
Attackers are exploiting CVE-2026-48842 against unpatched Roundcube servers months after a fix was released, raising urgency for organizations to update.
Sep 25, 2026
Roundcube patched a high-severity vulnerability four months ago. Attackers are now targeting systems that still have not installed the fix.
The flaw, tracked as CVE-2026-48842, is a pre-authentication SQL injection vulnerability affecting older Roundcube versions.
Canada’s cyber security agency warned on Sept. 21 that open-source reporting shows the flaw is being exploited in the wild, turning a previously patched issue into an active risk for organizations still running vulnerable servers.
Roundcube patched the vulnerability in two releases on May 24. The newly reported exploitation is therefore less about a newly discovered flaw than what happens after fixes become public.
Once a patch is available, attackers can compare...
Copyright of this story solely belongs to www.techrepublic.com. To see the full text click HERE