CuraSec

Act active

Roundcube Pre-Auth SQL Injection CVE-2026-48842 Actively Exploited

2026-09-25 15:49 UTC · The Hacker News · read the source ↗ #roundcube#sql-injection#active-exploitation
  • Engineer — Act: Active exploitation confirmed by a national cyber security authority plus a public PoC on GitHub makes this urgent despite low EPSS; patch Roundcube to 1.6.16 (1.6.x branch) or 1.7.1 (1.7.x branch) immediately on any self-hosted instance.
  • SOC/IR — Act: Pre-auth exploitation means no valid credentials needed, so assume-breach posture for any environment running Roundcube; sweep Roundcube database and web logs for anomalous virtuser_query parameter patterns dating back to when the PoC became public, and hunt for post-exploitation activity such as unexpected outbound connections from the webmail host.
  • Leader — Plan: Confirm whether self-hosted Roundcube is in use across internal systems or managed-service dependencies; if so, escalate to engineering for same-week patching given active exploitation of this webmail attack surface, which could expose sensitive communications or credentials.
  • Signals: CVE-2026-48842 — CISA KEV: not listed, EPSS 0.01, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.