Roundcube Webmail Instances Vulnerable to Code Execution Attacks (heise.de)
0xBASE INTEL BRIEF
- Eight vulnerabilities fixed in Roundcube Webmail 1.6.16 and 1.7.1.
- Four high-severity flaws allow code execution.
- No evidence of active exploitation yet.
"Roundcube Webmail versions 1.6.16 and 1.7.1 have been released, fixing eight security vulnerabilities. Four of these are rated 'high' severity (CVE-2026-48842, CVE-2026-48843, CVE-2026-48848, CVE-2026-48844). Without patches, attackers can execute arbitrary code via SQL injection and stored XSS. No active exploitation has been reported. Administrators are urged to update immediately."
#Roundcube
#security update
#vulnerabilities
no comments yet.