Roundcube Webmail CVE-2026-48842 active exploitation wave
Exploitation Wave
Summary
Hide ▲
Show ▼
Roundcube Webmail's CVE-2026-48842 is now in an active exploitation wave, putting more than 523,000 exposed instances at risk across the Internet. The flaw was patched in May and enables pre-auth SQL injection in the virtuser_query plugin, creating a broad attack surface for code-injection abuse. The wave matters because attackers can target a widely deployed mail platform that remains reachable at scale.
Related Happenings
Roundcube Webmail pre-auth SQL injection actively exploited (CVE-2026-48842)
Vulnerability
H score37
First: 24.09.2026 16:27
Last: 24.09.2026 16:27
Sources 1
How related:
A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security.
About this happening:
Roundcube Webmail's CVE-2026-48842 pre-auth SQL injection is being actively exploited, exposing internet-facing mail servers to authentication bypass and database comp...
Roundcube Webmail pre-auth SQL injection actively exploited (CVE-2026-48842)
VulnerabilityHow related: A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security.
About this happening: Roundcube Webmail's CVE-2026-48842 pre-auth SQL injection is being actively exploited, exposing internet-facing mail servers to authentication bypass and database comp...
Microsoft Exchange Server 2016/2019/SE authentication bypass (CVE-2026-62911)
Vulnerability
H score29
First: 01.09.2026 15:38
Last: 01.09.2026 15:38
Sources 1
About this happening:
An authentication bypass in Microsoft Exchange Server 2016/2019/SE leaves about 21,899 exposed servers at risk of mailbox takeover. The flaw is tracked as CVE-2026-6...
Microsoft Exchange Server 2016/2019/SE authentication bypass (CVE-2026-62911)
VulnerabilityAbout this happening: An authentication bypass in Microsoft Exchange Server 2016/2019/SE leaves about 21,899 exposed servers at risk of mailbox takeover. The flaw is tracked as CVE-2026-6...
UNK_MassTraction Roundcube university exploitation campaign
Campaign
H score41
First: 07.07.2026 12:10
Last: 07.07.2026 12:10
Sources 1
About this happening:
The UNK_MassTraction campaign is a China-linked activity targeting Roundcube webmail at U.S. and Canadian universities and related research organizations to steal...
UNK_MassTraction Roundcube university exploitation campaign
CampaignAbout this happening: The UNK_MassTraction campaign is a China-linked activity targeting Roundcube webmail at U.S. and Canadian universities and related research organizations to steal...
IceCube, SNOWLIGHT, and VShell Roundcube post-exploitation chain
Malware Activity
H score36
First: 07.07.2026 12:10
Last: 07.07.2026 12:10
Sources 1
About this happening:
IceCube is a Roundcube post-exploitation activity targeting U.S. and Canadian universities and related research organizations, with observed use since May against...
IceCube, SNOWLIGHT, and VShell Roundcube post-exploitation chain
Malware ActivityAbout this happening: IceCube is a Roundcube post-exploitation activity targeting U.S. and Canadian universities and related research organizations, with observed use since May against...
Roundcube Webmail actively exploited flaws (multiple vulnerabilities)
Vulnerability
H score33
First: 23.02.2026 13:44
Last: 23.02.2026 13:44
Sources 1
About this happening:
Roundcube Webmail remains an actively exploited vulnerability happening, with CVE-2025-49113 abused for unsafe PHP deserialization and code execution on vulner...
Roundcube Webmail actively exploited flaws (multiple vulnerabilities)
VulnerabilityAbout this happening: Roundcube Webmail remains an actively exploited vulnerability happening, with CVE-2025-49113 abused for unsafe PHP deserialization and code execution on vulner...
Latest development: 24.07.2026 09:50
TA458 is using Roundcube CVE-2025-49113 in a webmail exploitation chain that triggers unsafe PHP deserialization. The flaw gives attackers a route to code execution and persistent access on vulnerable instances.
Timeline
-
24.09.2026 16:27 2 articles · 1h ago
Canadian Centre warns that CVE-2026-48842 is actively exploited in Roundcube Webmail
Initial DisclosureThe Canadian Centre for Cyber Security warned that Roundcube Webmail CVE-2026-48842 is being actively exploited, after the flaw was patched in May as a pre-authenticated SQL injection in the virtuser_query built-in plugin. The agency urged administrators to secure their webmail servers, update to 1.6.16 or 1.7.1, or disable or remove virtuser_query if immediate upgrading is not possible, while Shadowserver tracks more than 523,000 Roundcube instances exposed on the Internet.
Show sources
- Hackers now exploit critical Roundcube flaw in code injection attacks — www.bleepingcomputer.com — 24.09.2026 16:27
- Hackers now exploit critical Roundcube flaw in code injection attacks — www.bleepingcomputer.com — 24.09.2026 16:27