Skip to content
Tech News
← Back to articles

Canadian cyber agency confirms active exploitation of Roundcube SQL injection flaw

read original more articles
GoKawiil Brief

The Canadian Centre for Cyber Security has updated its May advisory to warn that CVE-2026-48842, a pre-authenticated SQL injection bug in Roundcube Webmail's virtuser_query plugin, is now being exploited in the wild. Roundcube patched the flaw in May with versions 1.6.16 and 1.7.1, but Shadowserver still counts over 523,000 internet-exposed Roundcube instances, with no clear data on how many remain unpatched.

Why It Matters

GoKawiil's interpretation of the reporting above, not reported fact.

Roundcube underpins webmail for thousands of hosting providers and is bundled with cPanel, so unpatched servers could expose a large volume of email accounts to authentication bypass and data theft with no user interaction required. Roundcube flaws have previously drawn interest from state-linked hacking groups such as Winter Vivern, suggesting this vulnerability could attract similar attention now that exploitation is confirmed.

Key Takeaways

Source: bleepingcomputer.com, 2026-09-24

Published there as: “Hackers now exploit critical Roundcube flaw in code injection attacks”

Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.