Serial number:AV26-503
Date: May 25, 2026
Updated: September 21, 2026
On May 24, 2026, Roundcube published security advisories to address vulnerabilities in the following product:
- Roundcube Webmail – versions prior to 1.6.16
- Roundcube Webmail – versions prior to 1.7.1
Update 1
Open-source reporting indicates that CVE-2026-48842 is being exploited in the wild.
The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.


