DKDKCISSPSearch
Vulnerabilities

Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild.

DKCISSP News DeskThe Hacker News25 Sept 2026, 3:44 pm
Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild
Image courtesy of The Hacker News. Original report
DKCISSP REPORT

The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.

In an update shared this week, the Cyber Centre said the security flaw is being actively exploited in the wild, citing open-source reporting.

The Canadian Centre for Cyber Security warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild.

Data from the Shadowserver Foundation shows that there are more than 523,000 Roundcube instances exposed to the internet, with 10 of them flagged as vulnerable hosts as of September 23, 2026.

Way back in February 2026, two other vulnerabilities in the same product (CVE-2025-49113 and CVE-2025-68461) were tagged as actively exploited by the U.S.

In July 2026, Proofpoint said it identified a suspected China-aligned adversary dubbed UNK_MassTraction exploiting known security flaws in Roundcube to deliver web shells or a post-exploitation tool called VShell.

The issue stems from a preg_replace() backslash escape bypass that allows attackers to inject arbitrary SQL statements without authentication.

Patches for the vulnerability were released by Roundcube in May 2026 as part of 1.6.16 and 1.7.1.

Vulnerabilities in Roundcube have been an attractive target for threat actors looking to harvest sensitive email communications.

No more details of the exploitation activity have been disclosed.

What happened

The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.

In an update shared this week, the Cyber Centre said the security flaw is being actively exploited in the wild, citing open-source reporting.

What changed

The Canadian Centre for Cyber Security warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild.

Data from the Shadowserver Foundation shows that there are more than 523,000 Roundcube instances exposed to the internet, with 10 of them flagged as vulnerable hosts as of September 23, 2026.

Who is affected

Way back in February 2026, two other vulnerabilities in the same product (CVE-2025-49113 and CVE-2025-68461) were tagged as actively exploited by the U.S.

In July 2026, Proofpoint said it identified a suspected China-aligned adversary dubbed UNK_MassTraction exploiting known security flaws in Roundcube to deliver web shells or a post-exploitation tool called VShell.

Why it matters

The issue stems from a preg_replace() backslash escape bypass that allows attackers to inject arbitrary SQL statements without authentication.

Technical details

Patches for the vulnerability were released by Roundcube in May 2026 as part of 1.6.16 and 1.7.1.

Vulnerabilities in Roundcube have been an attractive target for threat actors looking to harvest sensitive email communications.

No more details of the exploitation activity have been disclosed.

Attribution

The Hacker News: The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild.

What to watch next

Watch for new exploitation reports and updated indicators of compromise.

Watch for updated vendor guidance and fixed-version details.

MORE IN VULNERABILITIES

More cybersecurity reporting

Critical FortiMail zero-day exploited in the wild (CVE-2026-104286) - Help Net SecurityHelp Net Security · 2 Oct 2026, 2:20 pmCritical FortiMail zero-day exploited in the wild (CVE-2026-104286) - Help Net SecurityHelp Net Security · 2 Oct 2026, 2:20 pmTwo Zero-Days Exploited in Attack on Dutch Institute for VulnerabilityInfosecurity Magazine · 2 Oct 2026, 1:55 pmTwo Zero-Days Exploited in Attack on Dutch Institute for VulnerabilityInfosecurity Magazine · 2 Oct 2026, 1:55 pm