Roundcube Webmail pre-auth SQL injection actively exploited (CVE-2026-48842)
Vulnerability
Summary
Hide ▲
Show ▼
Roundcube Webmail's CVE-2026-48842 pre-auth SQL injection is being actively exploited, exposing internet-facing mail servers to authentication bypass and database compromise. The flaw affects the virtuser_query plugin and was patched in May, but attackers are now using it in the wild. Successful exploitation can let an unauthenticated attacker execute malicious database commands and steal Roundcube data. Administrators need the fixed 1.6.16 or 1.7.1 releases, or to remove the vulnerable plugin if they cannot upgrade immediately.
Related Happenings
Roundcube Webmail CVE-2026-48842 active exploitation wave
Exploitation Wave
H score38
First: 24.09.2026 16:27
Last: 24.09.2026 16:27
Sources 1
How related:
A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security.
About this happening:
Roundcube Webmail's CVE-2026-48842 is now in an active exploitation wave, putting more than 523,000 exposed instances at risk across the Internet. The flaw was pat...
Roundcube Webmail CVE-2026-48842 active exploitation wave
Exploitation WaveHow related: A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security.
About this happening: Roundcube Webmail's CVE-2026-48842 is now in an active exploitation wave, putting more than 523,000 exposed instances at risk across the Internet. The flaw was pat...
UNK_MassTraction Roundcube university exploitation campaign
Campaign
H score41
First: 07.07.2026 12:10
Last: 07.07.2026 12:10
Sources 1
About this happening:
The UNK_MassTraction campaign is a China-linked activity targeting Roundcube webmail at U.S. and Canadian universities and related research organizations to steal...
UNK_MassTraction Roundcube university exploitation campaign
CampaignAbout this happening: The UNK_MassTraction campaign is a China-linked activity targeting Roundcube webmail at U.S. and Canadian universities and related research organizations to steal...
IceCube, SNOWLIGHT, and VShell Roundcube post-exploitation chain
Malware Activity
H score36
First: 07.07.2026 12:10
Last: 07.07.2026 12:10
Sources 1
About this happening:
IceCube is a Roundcube post-exploitation activity targeting U.S. and Canadian universities and related research organizations, with observed use since May against...
IceCube, SNOWLIGHT, and VShell Roundcube post-exploitation chain
Malware ActivityAbout this happening: IceCube is a Roundcube post-exploitation activity targeting U.S. and Canadian universities and related research organizations, with observed use since May against...
Storm-1175 high-tempo Medusa ransomware campaign
Campaign
H score59
First: 07.04.2026 13:02
Last: 07.04.2026 13:02
Sources 1
About this happening:
Storm-1175 is running a high-tempo Medusa ransomware campaign that has repeatedly exploited n-day and zero-day flaws to gain initial access before patching closes the...
Storm-1175 high-tempo Medusa ransomware campaign
CampaignAbout this happening: Storm-1175 is running a high-tempo Medusa ransomware campaign that has repeatedly exploited n-day and zero-day flaws to gain initial access before patching closes the...
Roundcube Webmail actively exploited flaws (multiple vulnerabilities)
Vulnerability
H score33
First: 23.02.2026 13:44
Last: 23.02.2026 13:44
Sources 1
About this happening:
Roundcube Webmail remains an actively exploited vulnerability happening, with CVE-2025-49113 abused for unsafe PHP deserialization and code execution on vulner...
Roundcube Webmail actively exploited flaws (multiple vulnerabilities)
VulnerabilityAbout this happening: Roundcube Webmail remains an actively exploited vulnerability happening, with CVE-2025-49113 abused for unsafe PHP deserialization and code execution on vulner...
Latest development: 24.07.2026 09:50
TA458 is using Roundcube CVE-2025-49113 in a webmail exploitation chain that triggers unsafe PHP deserialization. The flaw gives attackers a route to code execution and persistent access on vulnerable instances.
Timeline
-
24.09.2026 16:27 2 articles · 1h ago
Attackers actively exploit Roundcube Webmail CVE-2026-48842
Exploitation ObservedThe Canadian Centre for Cyber Security warned that attackers are actively exploiting Roundcube Webmail CVE-2026-48842, a pre-authenticated SQL injection in the virtuser_query plugin that was patched in May and can let unauthenticated attackers bypass authentication, execute malicious database commands, and steal data from Roundcube's database.
Show sources
- Hackers now exploit critical Roundcube flaw in code injection attacks — www.bleepingcomputer.com — 24.09.2026 16:27
- Hackers now exploit critical Roundcube flaw in code injection attacks — www.bleepingcomputer.com — 24.09.2026 16:27