Hackers Now Exploit Critical Roundcube Flaw in Code Injection Attacks
11 Articles
11 Articles
Critical Roundcube Webmail RCE Vulnerability CVE-2026-48842 Actively Exploited
Attackers are exploiting a critical unpatched vulnerability (CVE-2026-48842) in Roundcube webmail servers, enabling remote code execution via crafted emails without authentication. The flaw affects older versions and has been used to deploy web shells, steal data, and launch ransomware. Organizations must patch immediately.
Roundcube Webmail Under Attack: 523,000 Instances Exposed Online
Shadowserver is tracking more than 523,000 internet-accessible Roundcube Webmail instances as attackers exploit a high-severity vulnerability that can be abused without authentication. The Canadian Centre for Cyber Security updated its security advisory on Sept. 21 to warn that CVE-2026-48842 is being exploited in the wild. Roundcube originally patched the vulnerability in May, meaning organizations that have delayed updates could still be runni…
A SQL injection failure in Roundcube Webmail is being explored in real attacks. See how vulnerability CVE-2026-48842 affects your server and updates.
Roundcube CVE-2026-48842: Active Exploitation Reported for Pre-Authentication SQL Injection in virtuser_query
1. Basic Information Original Title: Roundcube security advisory (AV26-503) – Update 1 Source: Canadian Centre for Cyber Security Published: May 25, 2026 Updated: September 21, 2026 Collected: September 25, 2026, 08:28:50 +09:00 Report Type: Threat Intelligence Severity: High Severity Basis: Canadian cybersecurity authorities reported active exploitation based on public information for this pre-authentication SQL injection. The CVE CVSS v3.1 sco…
Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild
The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild. The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1. The issue stems from a preg_replace() backslash
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium










