If you run Roundcube webmail, or your hosting provider does, this one needs attention today. CVE-2026-48842 is a pre-authentication SQL injection in Roundcube that an attacker can hit with no login at all, and it is under active exploitation in the wild. Roundcube shipped the fix back in May 2026. The problem is the gap between “patch exists” and “patch applied,” and on shared hosting that gap is exactly where webmail installs sit and rot.
We clean up compromised hosting environments for a living, and webmail is one of the most reliably neglected surfaces on any server. It gets installed once, exposed to the internet permanently, and then nobody touches it until something goes wrong. That is the population getting hit right now.









