Find notable cyber news and cases, enriched with sources, timelines, and signals.

Roundcube Webmail pre-auth SQL injection actively exploited (CVE-2026-48842)

Vulnerability
First reported
Last updated
Happening score
H score 37
1 unique sources, 1 articles

Summary

Hide ▲

Roundcube Webmail's CVE-2026-48842 pre-auth SQL injection is being actively exploited, exposing internet-facing mail servers to authentication bypass and database compromise. The flaw affects the virtuser_query plugin and was patched in May, but attackers are now using it in the wild. Successful exploitation can let an unauthenticated attacker execute malicious database commands and steal Roundcube data. Administrators need the fixed 1.6.16 or 1.7.1 releases, or to remove the vulnerable plugin if they cannot upgrade immediately.

Related Happenings

Roundcube Webmail CVE-2026-48842 active exploitation wave

Exploitation Wave
H score38 First: 24.09.2026 16:27 Last: 24.09.2026 16:27 Sources 1

How related: A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security.

About this happening: Roundcube Webmail's CVE-2026-48842 is now in an active exploitation wave, putting more than 523,000 exposed instances at risk across the Internet. The flaw was pat...

UNK_MassTraction Roundcube university exploitation campaign

Campaign
H score41 First: 07.07.2026 12:10 Last: 07.07.2026 12:10 Sources 1

About this happening: The UNK_MassTraction campaign is a China-linked activity targeting Roundcube webmail at U.S. and Canadian universities and related research organizations to steal...

IceCube, SNOWLIGHT, and VShell Roundcube post-exploitation chain

Malware Activity
H score36 First: 07.07.2026 12:10 Last: 07.07.2026 12:10 Sources 1

About this happening: IceCube is a Roundcube post-exploitation activity targeting U.S. and Canadian universities and related research organizations, with observed use since May against...

Storm-1175 high-tempo Medusa ransomware campaign

Campaign
H score59 First: 07.04.2026 13:02 Last: 07.04.2026 13:02 Sources 1

About this happening: Storm-1175 is running a high-tempo Medusa ransomware campaign that has repeatedly exploited n-day and zero-day flaws to gain initial access before patching closes the...

Roundcube Webmail actively exploited flaws (multiple vulnerabilities)

Vulnerability
H score33 First: 23.02.2026 13:44 Last: 23.02.2026 13:44 Sources 1

About this happening: Roundcube Webmail remains an actively exploited vulnerability happening, with CVE-2025-49113 abused for unsafe PHP deserialization and code execution on vulner...

Latest development: 24.07.2026 09:50

TA458 is using Roundcube CVE-2025-49113 in a webmail exploitation chain that triggers unsafe PHP deserialization. The flaw gives attackers a route to code execution and persistent access on vulnerable instances.

Timeline

  1. 24.09.2026 16:27 2 articles · 1h ago

    Attackers actively exploit Roundcube Webmail CVE-2026-48842

    Exploitation Observed

    The Canadian Centre for Cyber Security warned that attackers are actively exploiting Roundcube Webmail CVE-2026-48842, a pre-authenticated SQL injection in the virtuser_query plugin that was patched in May and can let unauthenticated attackers bypass authentication, execute malicious database commands, and steal data from Roundcube's database.

    Show sources