Heise.De Roundcube Webmail Vulnerabilities Expose Systems to Malware Attacks
Article Content
- •Roundcube Webmail has eight vulnerabilities, four rated high severity.
- •Attack methods include SQL injection and Stored XSS, risking system compromise.
- •Security updates for versions 1.6.16 and 1.7.1 are available and should be applied immediately.
Roundcube Webmail has been found vulnerable due to eight security flaws, four of which are rated high severity (CVE-2026-48842, CVE-2026-48843, CVE-2026-48844, CVE-2026-48848). Attackers can exploit these vulnerabilities through SQL injection and Stored XSS attacks, potentially allowing them to execute malicious code on affected systems. Security updates for versions 1.6.16 and 1.7.1 have been released to address these issues. Administrators are urged to apply these patches immediately to mitigate risks. As of now, there are no reports of active exploitation of these vulnerabilities. The last security update was issued in March 2026, indicating a proactive approach to security by the developers.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track CVE-2026-48842 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Apple Patches CoreGraphics Zero-Day Exploited in Targeted Attacks Apple has released emergency updates for iOS, iPadOS, and macOS to address a critical zero-day vulnerability, CVE-2026-86950, in its CoreGraphics framework. This out-of-bounds write flaw can allow arbitrary code execution when a device processes a maliciously crafted file. The vulnerability was reportedly exploited in…
Active Exploitation of Roundcube SQL Injection Vulnerability CVE-2026-48842 CVE-2026-48842 is a critical pre-authentication SQL injection vulnerability in Roundcube Webmail's virtuser_query plugin, affecting versions prior to 1.6.16 and 1.7.1. The flaw allows unauthenticated attackers to inject arbitrary SQL statements, potentially compromising sensitive data such as mail account credentials…