Security News Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild TheHackerNews Daniel Bender 25 Sep 2026 Share Roundcube's patched CVE-2026-48842 SQL injection is actively exploited, affecting 1.6.x before 1.6.16 and 1.7.x before 1.7.1.