Act
active
Roundcube Pre-Auth SQL Injection CVE-2026-48842 Actively Exploited
- Engineer — Act: Active exploitation confirmed by a national cyber security authority plus a public PoC on GitHub makes this urgent despite low EPSS; patch Roundcube to 1.6.16 (1.6.x branch) or 1.7.1 (1.7.x branch) immediately on any self-hosted instance.
- SOC/IR — Act: Pre-auth exploitation means no valid credentials needed, so assume-breach posture for any environment running Roundcube; sweep Roundcube database and web logs for anomalous virtuser_query parameter patterns dating back to when the PoC became public, and hunt for post-exploitation activity such as unexpected outbound connections from the webmail host.
- Leader — Plan: Confirm whether self-hosted Roundcube is in use across internal systems or managed-service dependencies; if so, escalate to engineering for same-week patching given active exploitation of this webmail attack surface, which could expose sensitive communications or credentials.
- Signals: CVE-2026-48842 — CISA KEV: not listed, EPSS 0.01, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.