Critical SQL Injection and XSS Vulnerabilities in RoundcubeMail Affect Fedora Users
ID: 5c3d93d3-9289-511a-81cf-7646049655fb
STIX ID: report--5c3d93d3-9289-511a-81cf-7646049655fb
Feed Name: ThreatCluster
Critical SQL injection, cross-site scripting (XSS), SSRF, and privilege-escalation vulnerabilities were disclosed in RoundcubeMail packages for Fedora 43 and 44 (notably CVE-2026-48842 and CVE-2026-48843). The advisory urges immediate application of Fedora updates (RoundcubeMail 1.7.1 and 1.6.16 via dnf and advisories FEDORA-2026-2b956d89d3 / FEDORA-2026-07ee097ffe), hardening of LDAP autovalues and access controls, and monitoring of webmail logs; no specific indicators of active exploitation are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
