Frequency
3
occurrences
First Seen
May 27, 2026
Last Seen
June 4, 2026
Exploited in Wild
—
Ransomware Use
—
Public Exploits
—
Attack Vector
—
Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
Recent updates to RoundcubeMail for Fedora 43 and 44 revealed critical vulnerabilities, including SQL injection and cross-site scripting (XSS) issues. CVE-2026-48842 details a pre-auth SQL injection in the virtuser_query plugin, while CVE-2026-48843 highlights insufficient CSS sanitization leading t...
Roundcube Webmail has been found vulnerable due to eight security flaws, four of which are rated high severity (CVE-2026-48842, CVE-2026-48843, CVE-2026-48844, CVE-2026-48848). Attackers can exploit these vulnerabilities through SQL injection and Stored XSS attacks, potentially allowing them to exec...
Public Exploits
Checking GitHub for proof-of-concept code…