FOFA[verified]@fofabotPatch
The post announces two pre‑authentication SQL injection CVEs in Roundcube’s virtuser_query plugin, lists CVSS scores, and cites specific patch releases (1.6.16 / 1.7.1) for remediation.
Hunter[verified]@HunterMappingDisclosure
An alert announces new Roundcube Webmail CVEs with high CVSS scores, but offers no evidence of PoC, exploit tools, or detailed patch guidance.
ThreatWire[verified]@ThreatWire_Active Exploitation
CVE-2026-48842 is confirmed as actively exploited in the wild, with a PoC linked, technical details including pre-authentication SQL injection (CVSS 8.1) provided, and a patch/update to Roundcube 1.6.16/1.7.1 recommended.
Rıdvan Yağlı[verified]@ridvanyagliPoC
The tweet discloses CVE-2026-48842, a pre-authentication SQL Injection in Roundcube Webmail, linking a Python PoC on GitHub and listing affected and fixed versions, with no indication of active exploitation in the wild.
Rıdvan Yağlı[verified]@ridvanyagliPoC
The tweet announces a PoC for CVE-2026-48842, a pre‑auth SQL injection in Roundcube's virtuser_query plugin, and urges users to update to version 1.6.16, 1.7.1, or later.
Rıdvan Yağlı[verified]@ridvanyagliActive Exploitation
The tweet reports a pre‑auth SQL injection in Roundcube (CVE‑2026‑48842, CVSS 8.1) that is already being actively exploited in the wild, and urges users to update to the latest version to mitigate it.
N A I F[verified]@naif_aiydhActive Exploitation
CVE-2026-48842 is an unauthenticated SQL injection in Roundcube Webmail that is being actively exploited in the wild, with over 523,000 internet-exposed servers identified.
Cybersecurity News Everyday[verified]@TweetThreatNewsActive Exploitation
The tweet reports that CVE-2026-48842 in Roundcube is actively exploited in the wild via pre-auth SQL injection (virtuser_query) and possible auth bypass, with no patch or workaround mentioned.