Find notable cyber news and cases, enriched with sources, timelines, and signals.

Roundcube Webmail CVE-2026-48842 active exploitation wave

Exploitation Wave
First reported
Last updated
Happening score
H score 38
1 unique sources, 1 articles

Summary

Hide ▲

Roundcube Webmail's CVE-2026-48842 is now in an active exploitation wave, putting more than 523,000 exposed instances at risk across the Internet. The flaw was patched in May and enables pre-auth SQL injection in the virtuser_query plugin, creating a broad attack surface for code-injection abuse. The wave matters because attackers can target a widely deployed mail platform that remains reachable at scale.

Related Happenings

Roundcube Webmail pre-auth SQL injection actively exploited (CVE-2026-48842)

Vulnerability
H score37 First: 24.09.2026 16:27 Last: 24.09.2026 16:27 Sources 1

How related: A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security.

About this happening: Roundcube Webmail's CVE-2026-48842 pre-auth SQL injection is being actively exploited, exposing internet-facing mail servers to authentication bypass and database comp...

Microsoft Exchange Server 2016/2019/SE authentication bypass (CVE-2026-62911)

Vulnerability
H score29 First: 01.09.2026 15:38 Last: 01.09.2026 15:38 Sources 1

About this happening: An authentication bypass in Microsoft Exchange Server 2016/2019/SE leaves about 21,899 exposed servers at risk of mailbox takeover. The flaw is tracked as CVE-2026-6...

UNK_MassTraction Roundcube university exploitation campaign

Campaign
H score41 First: 07.07.2026 12:10 Last: 07.07.2026 12:10 Sources 1

About this happening: The UNK_MassTraction campaign is a China-linked activity targeting Roundcube webmail at U.S. and Canadian universities and related research organizations to steal...

IceCube, SNOWLIGHT, and VShell Roundcube post-exploitation chain

Malware Activity
H score36 First: 07.07.2026 12:10 Last: 07.07.2026 12:10 Sources 1

About this happening: IceCube is a Roundcube post-exploitation activity targeting U.S. and Canadian universities and related research organizations, with observed use since May against...

Roundcube Webmail actively exploited flaws (multiple vulnerabilities)

Vulnerability
H score33 First: 23.02.2026 13:44 Last: 23.02.2026 13:44 Sources 1

About this happening: Roundcube Webmail remains an actively exploited vulnerability happening, with CVE-2025-49113 abused for unsafe PHP deserialization and code execution on vulner...

Latest development: 24.07.2026 09:50

TA458 is using Roundcube CVE-2025-49113 in a webmail exploitation chain that triggers unsafe PHP deserialization. The flaw gives attackers a route to code execution and persistent access on vulnerable instances.

Timeline

  1. 24.09.2026 16:27 2 articles · 1h ago

    Canadian Centre warns that CVE-2026-48842 is actively exploited in Roundcube Webmail

    Initial Disclosure

    The Canadian Centre for Cyber Security warned that Roundcube Webmail CVE-2026-48842 is being actively exploited, after the flaw was patched in May as a pre-authenticated SQL injection in the virtuser_query built-in plugin. The agency urged administrators to secure their webmail servers, update to 1.6.16 or 1.7.1, or disable or remove virtuser_query if immediate upgrading is not possible, while Shadowserver tracks more than 523,000 Roundcube instances exposed on the Internet.

    Show sources