Attackers exploit Roundcube SQL injection CVE-2026-48842
Canada's Centre for Cyber Security warns that threat actors are exploiting CVE-2026-48842 (CVSS 8.1), an unauthenticated SQL injection in Roundcube's virtuser_query plugin. The flaw was fixed in versions 1.6.16 and 1.7.1, but over 500,000 Roundcube servers remain reachable online.
- CVE-2026-48842: SQL injection in virtuser_query plugin, CVSS 8.1
- Exploitation needs no authentication, bypasses preg_replace()
- Fixed in Roundcube 1.6.16 and 1.7.1
- Over 500,000 Roundcube servers exposed online
Read next
Security