www.cyber.gc.ca Critical Roundcube Flaw Actively Exploited in Attacks
Article Content
- •CVE-2026-48842 is a critical SQL injection vulnerability in Roundcube Webmail.
- •The vulnerability is actively exploited, allowing attackers to bypass authentication and execute commands.
- •Over 523,000 Roundcube instances are exposed online, increasing the risk of attacks.
A high-severity vulnerability in Roundcube Webmail, tracked as CVE-2026-48842, is now being actively exploited in the wild, as confirmed by the Canadian Centre for Cyber Security. This flaw, which allows pre-authenticated SQL injection attacks, enables threat actors to bypass authentication and execute malicious database commands without user interaction. Roundcube, widely used by various services, has urged users to update to versions 1.6.16 and 1.7.1 to mitigate the risk. The Cyber Center's advisory highlights the urgency for administrators to secure their webmail servers, especially since over 523,000 Roundcube instances are exposed online. Previous vulnerabilities in Roundcube have also been targets for cybercriminals and state-sponsored groups. The situation is critical, with ongoing attacks reported and no information on how many affected instances have been patched. Administrators unable to upgrade are advised to disable the vulnerable plugin to prevent exploitation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Apt28 and CVE-2020-12641 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Trellix Reports on Five Evasive Cyber Campaigns in 2026 Trellix's SecondSight Threat Hunting Report details five significant cyber campaigns from the first half of 2026, including APT28 and the Axios npm supply chain attack. Attackers exploited trusted infrastructures and employed advanced evasion techniques, such as using compromised government accounts and weaponizing…
Leaked Files Expose Russian Cyber Training for Military Operations Leaked documents reveal a structured training pipeline at Bauman Moscow State Technical University, aimed at preparing students for military cyber operations. The records indicate that graduates are funneled into GRU units linked to notorious hacking groups APT28 and Sandworm, known for espionage and sabotage…