security3 publishers
Canada's Cyber Centre flags live attacks on a pre-login Roundcube SQL injection
Canada's Cyber Centre says attackers are exploiting CVE-2026-48842, a no-login SQL injection in Roundcube's virtuser_query plugin rated 8.1. Only unpatched servers running that plugin are exposed, and Shadowserver flags 10 vulnerable hosts out of more than 523,000 online.
Perspective Coverage
3 publishers- Builder
- Builder 25%
- Operator
- Operator 70%
- Investor
- Investor 5%
Reality
- Evidence58
- Adoption22
- Hype gap+35
- Incentives
- Insufficient
- Confidence55