Index
Search
Search the public record. Drafts and scheduled notes are not included.
High
research
The Roundcube SQL injection is not in the CISA catalog
CVE-2026-48842 is a pre-authentication SQL injection in Roundcube virtuser_query, fixed in May 2026. A public PoC exists. CISA has not listed it, so ThreatWire does not mark Active Exploitation.
Published 1h ago
news
Opening the public record
ThreatWire is live as a record, not a firehose. X carries the short dispatch. The site carries the detail, and only after it is edited.
Published 8h ago
research
How ThreatWire records a vulnerability
The status on a ThreatWire card is an editorial claim. Unknown stays unknown until a public source confirms a PoC, an exploit, or active use.
Published 31h ago