Find notable cyber news and cases, enriched with sources, timelines, and signals.
Vulnerability Exploitation Wave

Roundcube CVE-2026-48842 Active Exploitation and Patch Pressure

Updated 25.09.2026 13:14
Case score 89
Members 2 First seen 24.09.2026 16:27 Latest activity 25.09.2026 13:14

Overview

**Roundcube Webmail** **CVE-2026-48842** is under active exploitation after being patched in May. The flaw is a pre-authenticated SQL injection in **virtuser_query** that can let unauthenticated attackers bypass authentication, run malicious database commands, and steal data from Roundcube's database. The activity has moved from patch availability to confirmed in-the-wild targeting, with administrators urged to update to **1.6.16** or **1.7.1** or disable the plugin if they cannot patch immediately. Available reporting also points to a large exposed internet-facing surface, while confirmed victim counts, operator attribution, and data-loss totals remain unconfirmed.
Latest development

Attackers actively exploit Roundcube Webmail CVE-2026-48842

The Canadian Centre for Cyber Security warned that attackers are actively exploiting Roundcube Webmail CVE-2026-48842, a pre-authenticated SQL injection in the virtuser_query plugin that was patched in May and can let unauthenticated attackers bypass authentication, execute malicious database commands, and steal data from Roundcube's database.

Signals

Impact signals
Exploitation
CVEs/products
Remediation

Threat actor context

2 listed

Technical intelligence

Existing Case data

Member happenings

Vulnerability Roundcube Webmail pre-auth SQL injection actively exploited (CVE-2026-48842)
Updated 24.09.2026 16:27 Lead Contribution 89
Exploitation Active Exploitation CVSS 8.1 High Patch Patch Available

**Roundcube Webmail**'s **CVE-2026-48842** pre-auth SQL injection is being **actively exploited**, exposing internet-facing mail servers to authentication bypass and database compromise. The flaw affects the **virtuser_query** plugin and was patched in **May**, but attackers are now using it in the wild. Successful exploitation can let an unauthenticated attacker execute malicious database commands and steal Roundcube data. Administrators need the fixed **1.6.16** or **1.7.1** releases, or to remove the vulnerable plugin if they cannot upgrade immediately.

Exploitation Wave Roundcube Webmail CVE-2026-48842 active exploitation wave
Updated 24.09.2026 16:27 Context
Exploitation Active Exploitation CVSS 8.1 High Patch Patch Available

**Roundcube Webmail**'s **CVE-2026-48842** is now in an **active exploitation wave**, putting more than **523,000 exposed instances** at risk across the Internet. The flaw was patched in **May** and enables **pre-auth SQL injection** in the **virtuser_query** plugin, creating a broad attack surface for code-injection abuse. The wave matters because attackers can target a widely deployed mail platform that remains reachable at scale.