Tech News
← Home  ·  All topics

Roundcube Webmail

1 GoKawiil brief on this topic

Canadian cyber agency confirms active exploitation of Roundcube SQL injection flaw

The Canadian Centre for Cyber Security has updated its May advisory to warn that CVE-2026-48842, a pre-authenticated SQL injection bug in Roundcube Webmail's virtuser_query plugin, is now being exploited in the wild. Roundcube patched the flaw in May with versions 1.6.16 and 1.7.1, but Shadowserver still counts over 523,000 internet-exposed Roundcube instances, with no clear data on how many remain unpatched.