Canadian cyber agency confirms active exploitation of Roundcube SQL injection flaw
The Canadian Centre for Cyber Security has updated its May advisory to warn that CVE-2026-48842, a pre-authenticated SQL injection bug in Roundcube Webmail's virtuser_query plugin, is now being exploited in the wild. Roundcube patched the flaw in May with versions 1.6.16 and 1.7.1, but Shadowserver still counts over 523,000 internet-exposed Roundcube instances, with no clear data on how many remain unpatched.