
Roundcube webmail flaw exploited in active attacks
A critical Roundcube Webmail vulnerability patched in May 2026 is now under active exploitation, with attackers injecting malicious code into unpatched instances.
15 stories tagged with this topic.

A critical Roundcube Webmail vulnerability patched in May 2026 is now under active exploitation, with attackers injecting malicious code into unpatched instances.

Arista Networks released emergency patches for a zero-day vulnerability in VeloCloud Orchestrator On-Prem deployments, which was being actively exploited in the wild.

ConnectWise has shared interim steps to reduce risk from a new vulnerability in its ScreenConnect remote-access software, with a fix due later this week.

cPanel released patches for a critical vulnerability allowing authenticated users with domain permissions to execute arbitrary code as root, affecting all supported versions of its control panel software.

CISA has ordered federal agencies to patch a critical Citrix NetScaler remote code execution vulnerability being actively exploited in attacks, with a deadline of this Saturday.

CERT Polska reports active exploitation of a critical remote-code-execution vulnerability in Zimbra Collaboration Suite, urging immediate patching for affected versions.

The U.S. Cybersecurity and Infrastructure Security Agency has confirmed that ransomware groups are exploiting a remote code execution vulnerability in Microsoft SharePoint, which has been under active attack since early July.

The U.S. Cybersecurity and Infrastructure Security Agency has added two recently patched SonicWall SMA1000 vulnerabilities to its Known Exploited Vulnerabilities catalog after confirming ransomware gangs are actively exploiting them.

Roundcube shipped 11 security fixes in versions 1.7.3 and 1.6.18 but assigned no CVE numbers, breaking automated detection for hosting fleets. cPanel has not yet integrated the update, extending exposure windows for providers relying on its bundled package.

WordPress 7.0.3 addresses 12 vulnerabilities, including pre-auth XSS on the login screen, SSRF in URL validation, and a multisite privilege escalation. Sites are urged to update immediately; backports to older branches are in progress.

SonicWall has released emergency fixes for two zero-day vulnerabilities in its SMA1000 secure access gateways after observing active exploitation. No customer impact details have been disclosed.

Microsoft has prolonged hotpatching support for Windows Server 2022 Datacenter: Azure Edition until October 2027, reducing reboot needs for eligible security updates but leaving broader patching workflows unchanged.

A critical vulnerability in SimpleHelp remote management software (CVE-2026-48558) allows unauthenticated attackers to create privileged technician accounts on servers with OIDC authentication enabled. The flaw affects versions 5.5.15 and older, with patches released June 9. Roughly 1,000 exposed servers may be vulnerable.

Cisco has released security updates for a zero-day vulnerability in Catalyst SD-WAN Manager (formerly vManage) that was actively exploited to gain root access. The flaw, tracked as CVE-2026-20262, affects all deployment types and stems from insufficient input validation during file uploads.

Aikido Security discovered a trivially exploitable authentication bypass in phpBB on June 2; a patch landed in version 3.3.17 four days later, though no fix yet exists for the 4.x alpha branch.