Critical Roundcube Webmail Flaw Actively Exploited in the Wild
Share
The Canadian Centre for Cyber Security has warned that a critical pre-authentication SQL injection vulnerability in Roundcube Webmail is being actively exploited in the wild.
The flaw, identified as CVE-2026-48842, carries a CVSS score of 8.1. It affects Roundcube Webmail versions 1.6.x prior to 1.6.16 and 1.7.x prior to 1.7.1.
Technical Details and Impact
The vulnerability resides within the virtuser_query plugin and is caused by a preg_replace() backslash escape bypass. This allows unauthenticated attackers to inject arbitrary SQL statements into the Roundcube database backend.
SentinelOne noted that unauthenticated attackers can use this method to potentially expose sensitive mail account credentials and stored messages. Because the exploit requires no prior authentication, it presents a high risk to internet-facing mail servers.
Exploitation Scale and Historical Context
Although Roundcube released patches for the issue in May 2026, active exploitation has been confirmed. Data from the Shadowserver Foundation shows that more than 523,000 Roundcube instances are currently exposed to the internet.
Roundcube has become a frequent target for advanced threat actors. In July 2026, Proofpoint identified a China-aligned adversary, known as UNK_MassTraction, exploiting Roundcube vulnerabilities to deploy web shells and post-exploitation tools like VShell.
The product has faced similar challenges earlier this year. In February 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) flagged two other Roundcube vulnerabilities, CVE-2025-49113 and CVE-2025-68461, as being actively exploited.
Remediation
To mitigate this risk, administrators should ensure that Roundcube Webmail is updated to version 1.6.16, 1.7.1, or the most recent stable release.




Leave a Reply