The Canadian Centre for Cyber Security has issued a warning regarding an actively exploited vulnerability in Roundcube Webmail. This flaw, identified as CVE-2026-48842, is a pre-authentication SQL injection issue with a CVSS score of 8.1, impacting Roundcube Webmail versions 1.6.x prior to 1.6.16 and 1.7.x before 1.7.1.
Understanding the Vulnerability
This critical vulnerability arises from a backslash escape bypass in the preg_replace() function within the virtuser_query plugin, enabling attackers to execute arbitrary SQL commands without requiring authentication. As SentinelOne highlights, such unauthorized SQL injections could potentially reveal mail account credentials and stored email contents.
Roundcube addressed this security gap by releasing patches in May 2026, corresponding to versions 1.6.16 and 1.7.1. Despite these updates, the Canadian Cyber Centre notes that the vulnerability is being exploited in real-world scenarios, as evidenced by open-source intelligence.
Current Exploitation Landscape
According to the Shadowserver Foundation, over 523,000 Roundcube instances are visible on the internet, with a small subset of 10 identified as vulnerable as of late September 2026. This underscores the ongoing risk and the need for immediate protective measures.
Historically, vulnerabilities in Roundcube have attracted cybercriminals aiming to access sensitive email communications. Proofpoint reported in July 2026 that a suspected China-affiliated group, UNK_MassTraction, exploited known vulnerabilities in Roundcube to deploy web shells and a post-exploitation tool called VShell.
Previous Vulnerabilities and Ongoing Threats
Earlier in February 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) highlighted two other Roundcube vulnerabilities, CVE-2025-49113 and CVE-2025-68461, as being actively exploited. This pattern of exploitation underscores the persistent interest of threat actors in compromising email security through Roundcube.
Given the active exploitation of these vulnerabilities, organizations using Roundcube Webmail are urged to apply the latest security patches promptly. It remains crucial to stay vigilant against emerging threats and ensure robust cybersecurity practices to protect sensitive information.
