Canadian cyber agency confirms active exploitation of Roundcube SQL injection flaw
The Canadian Centre for Cyber Security has updated its May advisory to warn that CVE-2026-48842, a pre-authenticated SQL injection bug in Roundcube Webmail's virtuser_query plugin, is now being exploited in the wild. Roundcube patched the flaw in May with versions 1.6.16 and 1.7.1, but Shadowserver still counts over 523,000 internet-exposed Roundcube instances, with no clear data on how many remain unpatched.
GoKawiil's interpretation of the reporting above, not reported fact.
Roundcube underpins webmail for thousands of hosting providers and is bundled with cPanel, so unpatched servers could expose a large volume of email accounts to authentication bypass and data theft with no user interaction required. Roundcube flaws have previously drawn interest from state-linked hacking groups such as Winter Vivern, suggesting this vulnerability could attract similar attention now that exploitation is confirmed.
- CVE-2026-48842 is a pre-auth SQL injection in Roundcube's virtuser_query plugin, patched in May.
- Canada's Cyber Centre confirmed active exploitation four months after the patch was released.
- Admins unable to update immediately are advised to disable or remove the virtuser_query plugin.
Source: bleepingcomputer.com, 2026-09-24
Published there as: “Hackers now exploit critical Roundcube flaw in code injection attacks”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.