Skip to content

Topic

Webmail security

Vulnerabilities, attacks and defences affecting browser-based email clients and the mail servers behind them.

Current clusters

security3 publishers

Canada's Cyber Centre flags live attacks on a pre-login Roundcube SQL injection

Canada's Cyber Centre says attackers are exploiting CVE-2026-48842, a no-login SQL injection in Roundcube's virtuser_query plugin rated 8.1. Only unpatched servers running that plugin are exposed, and Shadowserver flags 10 vulnerable hosts out of more than 523,000 online.

Perspective Coverage

3 publishers
Builder
Builder 25%
Operator
Operator 70%
Investor
Investor 5%

Reality

Evidence58
Adoption22
Hype gap+35
Incentives
Insufficient
Confidence55