Roundcube Webmail Vulnerability in Attackers’ Crosshairs
Roundcube Webmail vulnerability CVE-2026-48842 is being exploited in the wild.
Summary
Threat actors are actively exploiting a critical SQL injection vulnerability (CVE-2026-48842) in the Roundcube webmail client's virtuser_query plugin. This unauthenticated vulnerability allows attackers to tamper with database operations, access sensitive user data, and map authentication workflows. Roundcube has released patches in versions 1.6.16 and 1.7.1.
Full text
Threat actors have been exploiting a high-severity vulnerability in Roundcube, the popular open source webmail client, the Canadian Centre for Cyber Security warns. Tracked as CVE-2026-48842 (CVSS score of 8.1), the security defect is described as an SQL injection in the virtuser_query plugin that can be exploited without authentication. The plugin resolves email addresses to mailbox usernames and uses the preg_replace() filter with backslash escaping to neutralize injection attempts. CVE-2026-48842, however, allows attackers to bypass the protection by using crafted queries containing backslash sequences that defeat the plugin’s regular-expression escaping mechanism. The attacker’s malicious input invokes the virtuser_query plugin to traverse the preg_replace() filter, resulting in quote characters being concatenated into an SQL string that is sent to the database, SentinelOne explains. Roundcube resolved the vulnerability in versions 1.6.16 and 1.7.1, which were released in late May.Advertisement. Scroll to continue reading. This week, the Canadian Centre for Cyber Security warned that threat actors have been exploiting it in attacks, but did not share details on the observed exploitation. “Open-source reporting indicates that CVE-2026-48842 is being exploited in the wild,” the Cyber Centre said. As Paymob information security lead Omar Ahmed points out, successful exploitation of the bug allows attackers to tamper with database operations, access protected information, access user identities, messages, and address books, and map authentication workflows and admin functions. Data from the non-profit organization The Shadowserver Foundation shows that there are over 500,000 Roundcube servers accessible from the internet, but it is unclear how many of them are vulnerable. Vulnerabilities in Roundcube servers are frequently targeted by threat actors. Some examples include CVE-2025-68461, CVE-2025-49113, and CVE-2024-37383. Related: SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted Related: Critical WordPress Vulnerability Exploited Immediately After Disclosure Related: Adobe Patches Critical Flaws in Connect, AEM Forms Related: Check Point Patches Exploited Management Server Zero-Day Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Astrana Health Data Breach Impacts Private, Confidential InformationCritical WordPress Vulnerability Exploited Immediately After DisclosureAdobe Patches Critical Flaws in Connect, AEM FormsChrome 154 Patches 108 VulnerabilitiesArista Urges Immediate Patching of Exploited VCO Zero-DayCritical F5 BIG-IP Vulnerability Exploited as Zero-DayCheck Point Patches Exploited Management Server Zero-DayBigCommerce Data Stolen via Ribon Apps Hack Latest News Autonomous AI Hacks Raise Thorny Questions of Legal AccountabilityKontext Security Emerges With $4 Million for AI Agent Runtime ControlsOpenAI Agents Probed Websites for Vulnerabilities While Fetching Public DataAI-Powered Campaign Targets Hundreds of Online RetailersIsland Raises $400 Million at $6.4 Billion ValuationOT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS IntegratorsBegin at the End: How to Enable Agentic RemediationSolarWinds Patches Critical RCE Flaws in Observability Self-Hosted Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Building Continuous Authorization at Scale September 23, 2026 Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required. Register People on the MoveGwen Gann has become State Chief Information Security Officer for the State of Washington at WaTech.Pietr Lindahal has been named Vice President and Chief Information Security Officer at Boston Scientific.AI agent identity and enforcement company FIOR has appointed Gemma Ungoed-Thomas as Adviser.More People On The MoveExpert Insights Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) Flipboard Reddit Whatsapp Whatsapp Email
Indicators of Compromise
- cve — CVE-2026-48842
- cve — CVE-2025-68961
- cve — CVE-2025-49113
- cve — CVE-2024-37383