Actively Exploited Roundcube Flaw Lets Attackers Slip Past the Login Screen Entirely
Canadian cybersecurity officials have confirmed active, in-the-wild exploitation of a pre-authentication SQL injection vulnerability in Roundcube Webmail, tracked as CVE-2026-48842. The flaw requires no valid credentials to exploit,...
Roundcube Patches a Dozen Flaws, Including a Zero-Click Webmail XSS and an IPv6-Based SSRF Bypass
The Roundcube team has shipped versions 1.6.19 and 1.7.4 to close twelve security holes, headlined by a stored cross-site scripting bug that fires the moment a crafted email...
Roundcube Patches Eleven Flaws, Including Remote Code Execution Reachable Through Spam-Learning Plugin
Roundcube 1.6.18 and 1.7.3 close eleven vulnerabilities, headlined by a remote code execution bug in the markasjunk plugin and two SSRF filter bypasses. No in-the-wild exploitation has been...
Critical Roundcube vulnerability (CVE-2025-49113): exploit sold in Darknet as “Email Armageddon” looms
A decade-old Remote Code Execution (RCE) flaw in Roundcube, the widely used open-source email client, has escalated into a global cybersecurity emergency. Designated CVE-2025-49113 with a near-maximum CVSS...