Roundcube Webmail Vulnerability Actively Exploited in the Wild, Cyber Centre Warns
A critical pre-authentication SQL injection vulnerability in **Roundcube Webmail** (**CVE-2026-48842**) is being actively exploited, according to a recent warning from the Canadian Centre for Cyber Security. Despite patches released in May 2026, many instances remain vulnerable, posing a significant risk of credential exposure and data theft.
The Canadian Centre for Cyber Security has issued an urgent alert regarding a **Roundcube Webmail** vulnerability, **CVE-2026-48842**, which is now under active exploitation. This critical flaw, with a CVSS score of 8.1, is a pre-authentication SQL injection affecting **Roundcube Webmail** versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.

### The Nature of the Vulnerability
The root cause of **CVE-2026-48842** lies in a `preg_replace()` backslash escape bypass within the `virtuser_query` plugin. This allows unauthenticated attackers to inject arbitrary SQL statements into **Roundcube's** database backend. Cybersecurity firm **SentinelOne** highlighted the severity, stating, "Unauthenticated attackers can inject SQL into **Roundcube's** database backend through the `virtuser_query` plugin, potentially exposing mail account credentials and stored messages."
### Patches and Ongoing Risks
**Roundcube** released patches for this vulnerability in May 2026, with updates to versions 1.6.16 and 1.7.1. However, the Canadian Cyber Centre's recent update confirms that active exploitation is occurring, citing open-source intelligence. Specific details of the ongoing attacks have not yet been disclosed.
Data from the **Shadowserver Foundation** reveals a concerning landscape: over 523,000 **Roundcube** instances are exposed to the internet. As of September 23, 2026, at least 10 of these have been flagged as vulnerable hosts, underscoring the widespread potential for compromise.
### A History of Exploitation
This is not the first time **Roundcube** vulnerabilities have attracted the attention of threat actors. In July 2026, **Proofpoint** identified a suspected China-aligned group, dubbed **UNK_MassTraction**, exploiting known **Roundcube** security flaws. Their objective was to deploy web shells or a post-exploitation tool named **VShell**.
Further back, in February 2026, the U.S. Cybersecurity and Infrastructure Security Agency (**CISA**) added two other **Roundcube** vulnerabilities, **CVE-2025-49113** and **CVE-2025-68461**, to its list of actively exploited flaws. This pattern of exploitation highlights the critical importance of keeping **Roundcube** installations fully updated and regularly audited for security integrity.