Attackers Target Unpatched Roundcube Servers With CVE-2026-48842

https://assets.techrepublic.com/uploads/2026/09/mail.png?f=jpeg

Months after a flaw was patched, threat actors are now betting that not everyone got the patch. Image: Mariia Berezovsky/Unsplash

Attackers are exploiting CVE-2026-48842 against unpatched Roundcube servers months after a fix was released, raising urgency for organizations to update.

Sep 25, 2026

Roundcube patched a high-severity vulnerability four months ago. Attackers are now targeting systems that still have not installed the fix.

The flaw, tracked as CVE-2026-48842, is a pre-authentication SQL injection vulnerability affecting older Roundcube versions.

Canada’s cyber security agency warned on Sept. 21 that open-source reporting shows the flaw is being exploited in the wild, turning a previously patched issue into an active risk for organizations still running vulnerable servers.

Roundcube patched the vulnerability in two releases on May 24. The newly reported exploitation is therefore less about a newly discovered flaw than what happens after fixes become public.

Once a patch is available, attackers can compare...

Copyright of this story solely belongs to www.techrepublic.com. To see the full text click HERE

Read more

https://images.siliconangle.com/blogs.dir/1/files/2026/09/Screenshot-from-2026-09-22-08-35-11.png

Relay, which develops cloud-hosted, AI-powered smart radio communicators for frontline workers, raised $36M to help businesses capture “frontline intelligence”

Sponsor Posts Subquadratic: the LLM built for 12M-token reasoning — SubQ can reason across entire codebases and document sets in one pass with no RAG workarounds. Read how SubQ 1.1 Small holds near-perfect retrieval out to 12M tokens. Introducing Campus: The digital home for educational institutions — Every educational institution needs