logo

Critical SQL Injection and XSS Vulnerabilities in RoundcubeMail Affect Fedora Users

ID: 5c3d93d3-9289-511a-81cf-7646049655fb

STIX ID: report--5c3d93d3-9289-511a-81cf-7646049655fb

Feed Name: ThreatCluster

Threat Score
74/100

Date Published: 2026-06-04

Date Updated: 2026-06-08

...
...

Critical SQL injection, cross-site scripting (XSS), SSRF, and privilege-escalation vulnerabilities were disclosed in RoundcubeMail packages for Fedora 43 and 44 (notably CVE-2026-48842 and CVE-2026-48843). The advisory urges immediate application of Fedora updates (RoundcubeMail 1.7.1 and 1.6.16 via dnf and advisories FEDORA-2026-2b956d89d3 / FEDORA-2026-07ee097ffe), hardening of LDAP autovalues and access controls, and monitoring of webmail logs; no specific indicators of active exploitation are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.