Vulnerability
Exploitation Wave
Roundcube CVE-2026-48842 Active Exploitation and Patch Pressure
Updated 25.09.2026 13:14
Case score 89
Why this score?
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 89
- Main story score
- 89
- Related evidence lift
- +0 / 20
- Contributing updates
- 0
- Context updates
- 0
Top contributors
- Vulnerability Primary vulnerability record for CVE-2026-48842, including flaw mechanics, affected versions, and patch context. main
- Exploitation Wave Confirms that the same Roundcube flaw is now under active exploitation and adds current mitigation urgency. main
Members 2
First seen 24.09.2026 16:27
Latest activity 25.09.2026 13:14
Overview
**Roundcube Webmail** **CVE-2026-48842** is under active exploitation after being patched in May. The flaw is a pre-authenticated SQL injection in **virtuser_query** that can let unauthenticated attackers bypass authentication, run malicious database commands, and steal data from Roundcube's database.
The activity has moved from patch availability to confirmed in-the-wild targeting, with administrators urged to update to **1.6.16** or **1.7.1** or disable the plugin if they cannot patch immediately. Available reporting also points to a large exposed internet-facing surface, while confirmed victim counts, operator attribution, and data-loss totals remain unconfirmed.
Latest development
Attackers actively exploit Roundcube Webmail CVE-2026-48842
The Canadian Centre for Cyber Security warned that attackers are actively exploiting Roundcube Webmail CVE-2026-48842, a pre-authenticated SQL injection in the virtuser_query plugin that was patched in May and can let unauthenticated attackers bypass authentication, execute malicious database commands, and steal data from Roundcube's database.
Attackers are actively exploiting **CVE-2026-48842** in **Roundcube Webmail**, turning a flaw patched in May into an immediate risk for internet-facing mail servers. The vulnerability is a pre-authenticated SQL injection in the **virtuser_query** built-in plugin and can let an unauthenticated attacker bypass authentication, execute malicious database commands, and steal data from Roundcube's database. Affected versions include **1.6.x before 1.6.16** and **1.7.x before 1.7.1**.
Current defensive guidance is to upgrade to **1.6.16** or **1.7.1** and, if that cannot be done immediately, disable or remove **virtuser_query**. Available reporting also describes a broad internet-facing surface, with more than **523,000 Roundcube instances** exposed and **10 hosts** flagged as vulnerable as of September 23, 2026; those figures describe exposure and identified vulnerable hosts, not confirmed compromises. Available evidence does not identify a confirmed victim count, a named operator for this exploitation, or a quantified data-loss total.
The sequence has moved from vendor remediation into active exploitation warnings from the Canadian Centre for Cyber Security, so the main change is confirmation that unpatched Roundcube deployments are now being targeted. The operational priority is to find exposed Roundcube systems using the vulnerable plugin, patch them, and disable or remove **virtuser_query** wherever immediate upgrading is not possible.
Signals
Impact signals
Exploitation
CVEs/products
Remediation
Threat actor context
2 listedTechnical intelligence
Existing Case dataMember happenings
Vulnerability
Roundcube Webmail pre-auth SQL injection actively exploited (CVE-2026-48842)
Exploitation
Active Exploitation
CVSS
8.1 High
Patch
Patch Available
Vulnerability
Roundcube Webmail pre-auth SQL injection actively exploited (CVE-2026-48842)
Exploitation
Active Exploitation
CVSS
8.1 High
Patch
Patch Available
Exploitation Wave
Roundcube Webmail CVE-2026-48842 active exploitation wave
Exploitation
Active Exploitation
CVSS
8.1 High
Patch
Patch Available
Exploitation Wave
Roundcube Webmail CVE-2026-48842 active exploitation wave
Exploitation
Active Exploitation
CVSS
8.1 High
Patch
Patch Available