The Canadian Centre for Cyber Security has issued a warning that a recently patched Roundcube Webmail vulnerability is now being actively exploited by attackers in real-world campaigns.
Tracked as CVE-2026-48842 with a CVSS score of 8.1, the flaw affects the virtuser_query plugin in Roundcube Webmail versions 1.6.x prior to 1.6.16 and 1.7.x prior to 1.7.1. The security issue is a pre-authentication SQL injection vulnerability, allowing attackers to execute malicious database queries without needing to log in.
The vulnerability arises from a preg_replace() backslash escape bypass, which can be abused to inject arbitrary SQL commands into the application's backend database. According to SentinelOne, unauthenticated threat actors can exploit the flaw through the virtuser_query plugin, potentially gaining access to sensitive email account credentials and stored mailbox data.
Roundcube addressed the weakness in May 2026 with the release of versions 1.6.16 and 1.7.1, which contain the necessary security fixes.
In an advisory released this week, the Cyber Centre confirmed that the vulnerability is now being exploited in active attacks, citing publicly available reporting. However, officials have not released further details regarding the threat actors involved or the scale of the ongoing exploitation.
Internet exposure data from the Shadowserver Foundation indicates that more than 523,000 Roundcube instances are currently accessible online. As of September 23, 2026, at least 10 exposed systems were identified as still vulnerable to the flaw.
Roundcube has long been a favored target for cyber espionage and cybercriminal operations due to its widespread use in web-based email environments. In July 2026, security researchers at Proofpoint reported that a suspected China-aligned threat group known as UNK_MassTraction exploited known Roundcube vulnerabilities to deploy web shells and a post-compromise tool called VShell.
Earlier, in February 2026, two additional Roundcube vulnerabilities, CVE-2025-49113 and CVE-2025-68461, were added to the list of actively exploited flaws by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), further highlighting the platform's continued appeal to threat actors seeking unauthorized access to sensitive email communications.
Found this article interesting? Follow us on X(Twitter) ,Threads and FaceBook to read more exclusive content we post.
