Back Securityweek Roundcube Webmail Vulnerability in Attackers' Crosshairs
Threat actors have been exploiting a high-severity vulnerability in Roundcube, the popular open source webmail client, the Canadian Centre for Cyber Security warns.
Tracked as CVE-2026-48842 (CVSS score of 8.1), the security defect is described as an SQL injection in the virtuser_query plugin that can be exploited without authentication.
The plugin resolves email addresses to mailbox usernames and uses the preg_replace() filter with backslash escaping to neutralize injection attempts.
CVE-2026-48842, however, allows attackers to bypass the protection by using crafted queries containing backslash sequences that defeat the plugin’s regular-expression escaping mechanism.
The attacker’s malicious input invokes the virtuser_query plugin to traverse the preg_replace() filter, resulting in quote characters being concatenated into an SQL string that is sent to the database, SentinelOne explains .
Roundcube resolved the vulnerability in versions 1.6.16 and 1.7.1 , which were released in late May.
This week, the Canadian Centre for Cyber Security warned that threat actors have been exploiting it in attacks, but did not details on the observed exploitation.
“Open-source reporting indicates that CVE-2026-48842 is being exploited in the wild,” the Cyber Centre said.
As Paymob information security lead Omar Ahmed points out , successful exploitation of the bug allows attackers to tamper with database operations, access protected information, access user identities, messages, and address books, and map authentication workflows and admin functions.
Data from the non-profit organization The Shadowserver Foundation shows that there are over 500,000 Roundcube servers accessible from the internet, but it is unclear how many of them are vulnerable.
Vulnerabilities in Roundcube servers are frequently targeted by threat actors. Some examples include CVE-2025-68461 , CVE-2025-49113 , and CVE-2024-37383 .
Related: SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted
Related: Critical WordPress Vulnerability Exploited Immediately After Disclosure
Related: Adobe Patches Critical Flaws in Connect, AEM Forms
Related: Check Point Patches Exploited Management Server Zero-Day
Ionut Arghire is an international correspondent for SecurityWeek.
More from Ionut Arghire
AI-Powered Campaign Targets Hundreds of Online Retailers
SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted
Astrana Health Data Breach Impacts Private, Confidential Information
Critical WordPress Vulnerability Exploited Immediately After Disclosure
Adobe Patches Critical Flaws in Connect, AEM Forms
Chrome 154 Patches 108 Vulnerabilities
Arista Urges Immediate Patching of Exploited VCO Zero-Day
Critical F5 BIG-IP Vulnerability Exploited as Zero-Day
In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure
North Korea Suspected in $351 Million Bitget Crypto Heist
CISA Election Security Plan Flags Patching Barriers, Voter Database Attacks
Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court
Windows, Linux, Android File Notification Systems Leak User Activity
‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration
Autonomous AI Hacks Raise Thorny Questions of Legal Accountability
Kontext Security Emerges With $4 Million for AI Agent Runtime Controls
Flipboard Whatsapp Whatsapp Email
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
