Skip to content
Critical Roundcube Flaw Actively Exploited in Attacks

Critical Roundcube Flaw Actively Exploited in Attacks

First seen 24 Sep 2026, 18:01 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 24, 2026 at 20:52 UTC
  • •CVE-2026-48842 is a critical SQL injection vulnerability in Roundcube Webmail.
  • •The vulnerability is actively exploited, allowing attackers to bypass authentication and execute commands.
  • •Over 523,000 Roundcube instances are exposed online, increasing the risk of attacks.

A high-severity vulnerability in Roundcube Webmail, tracked as CVE-2026-48842, is now being actively exploited in the wild, as confirmed by the Canadian Centre for Cyber Security. This flaw, which allows pre-authenticated SQL injection attacks, enables threat actors to bypass authentication and execute malicious database commands without user interaction. Roundcube, widely used by various services, has urged users to update to versions 1.6.16 and 1.7.1 to mitigate the risk. The Cyber Center's advisory highlights the urgency for administrators to secure their webmail servers, especially since over 523,000 Roundcube instances are exposed online. Previous vulnerabilities in Roundcube have also been targets for cybercriminals and state-sponsored groups. The situation is critical, with ongoing attacks reported and no information on how many affected instances have been patched. Administrators unable to upgrade are advised to disable the vulnerable plugin to prevent exploitation.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2020-05-04
CVE-2020-12641 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2020-12-28
CVE-2020-35730 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2021-11-19
CVE-2021-44026 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2023-10-18
CVE-2023-5631 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-06-02
CVE-2025-49113 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-12-18
CVE-2025-68461 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-25
CVE-2026-48842 published
Roundcube security team disclosed a critical SQL injection vulnerability affecting versions prior to 1.6.16 and 1.7.1.
BleepingComputer
2026-09-24
Active exploitation confirmed
The Canadian Centre for Cyber Security warned that CVE-2026-48842 is being exploited in the wild, urging immediate action from administrators.
BleepingComputer
2026-09-24
Cyber Center advisory issued
The Cyber Centre published an advisory encouraging users to apply updates to mitigate the vulnerability.
www.cyber.gc.ca

More articles in this cluster (3)

Following this threat?

Track Apt28 and CVE-2020-12641 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed