Roundcube SQL injection CVE-2026-48842 exploited in the wild
Canada's Centre for Cyber Security warned on September 21 that CVE-2026-48842 (CVSS 8.1) in Roundcube is being exploited in the wild. The pre-auth SQL injection in the virtuser_query plugin affects 1.6.x before 1.6.16 and 1.7.x before 1.7.1; the fix shipped on May 24, 2026.
- CVE-2026-48842 (CVSS 8.1) is a pre-auth SQL injection in the virtuser_query plugin
- Roundcube 1.6.x before 1.6.16 and 1.7.x before 1.7.1 are vulnerable; patch out May 24
- Exploitation requires no account or user interaction
- Successful attacks can expose mailbox credentials and stored messages
Read next
Security