Index
Search
Search the public record. Drafts and scheduled notes are not included.
High
research
The Roundcube SQL injection is not in the CISA catalog
CVE-2026-48842 is a pre-authentication SQL injection in Roundcube virtuser_query, fixed in May 2026. A public PoC exists. CISA has not listed it, so ThreatWire does not mark Active Exploitation.
Published 2h ago
HighPoC Available
CVE-2026-48842
Roundcube virtuser_query SQL injection
SQLi
Published 25 May 2026