Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild
AI-summarised brief · reviewed before publication
The Canadian Centre for Cyber Security has warned that the pre‑authentication SQL injection flaw CVE‑2026‑48842 in Roundcube Webmail’s virtuser_query plugin is actively exploited. The vulnerability, affecting versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1, allows attackers to inject SQL without authentication, potentially exposing mail credentials and messages. Roundcube released patches in May 2026, yet the Cyber Centre reports ongoing exploitation. Shadowserver data shows over 523,000 exposed instances, with 10 currently vulnerable. Previous Roundcube flaws have also been targeted by state‑aligned actors.
💡 Why It Matters
- · The active exploitation of a patched vulnerability demonstrates attackers’ rapid pivot to new targets, underscoring the urgency for organizations to verify patch deployment and monitor for anomalous database activity.