Hackers now exploit critical Roundcube flaw in code injection attacks
Canada's Centre for Cyber Security warns that CVE-2026-48842, a Roundcube Webmail flaw patched in May, is now being actively exploited. The pre-authenticated SQL injection in the virtuser_query plugin lets attackers bypass authentication and steal database data. Over 523,000 Roundcube instances are exposed online.
- CVE-2026-48842 is a pre-auth SQL injection in the virtuser_query plugin
- Exploitation needs no privileges and no user interaction
- Fixed in Roundcube versions 1.6.16 and 1.7.1
- Over 523,000 Roundcube instances exposed on the Internet
Read next
Security