INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Roundcube Webmail Vulnerability Exploited in the Wild via SQL Injection
| 2026-09-25 06:57 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
A critical vulnerability in Roundcube webmail has been exploited in the wild, putting over 500,000 servers at risk of database compromise. The vulnerability, tracked as CVE-2026-48842, affects versions before 1.6.16 and 1.7.1, with a CVSS score of 8.1. An unauthenticated attacker can inject SQL into the virtuser_query plugin, potentially exposing mail account credentials and stored messages. This exploit is particularly concerning as it allows an attacker to access the database without authentication. The vulnerability was patched four months ago on May 24, 2026, but its exploitation in the wild highlights a need for increased vigilance among organizations using Roundcube webmail.
Technical Mitigations AI-generated
• Implement input validation and sanitization for the virtuser_query plugin to prevent SQL injection attacks.
• Use prepared statements or parameterized queries instead of string-based SQL queries to reduce the risk of SQL injection vulnerabilities.
• Regularly update and patch Roundcube versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1, as well as ensure that all plugins are up-to-date, especially the virtuser_query plugin.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Winter VivernWinter VivernAPT28APT28
CVE-2026-48842CVE-2026-48842
CVE-2025-68461CVE-2025-68461
CVE-2020-35730CVE-2020-35730
CVE-2024-37383CVE-2024-37383
CVE-2025-49113CVE-2025-49113
CVE-2021-44026CVE-2021-44026
CVE-2023-5631CVE-2023-5631
CVE-2020-12641CVE-2020-12641
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
governmentgovernment
Incident Timeline
May 2022
Threat actors have exploited 11 previously tagged Roundcube Webmail vulnerabilities, CVE-2026-48842 being one of them, since May 2022.
Click on any entity below to view its context and source!
infrastructure
Roundcube
Since May 2022, the cybersecurity agency
has tagged 11 Roundcube Webmail vulnerabilities
as exploited in the wild.
general_metric
11 Roundcube Webmail
Since May 2022, the cybersecurity agency
has tagged 11 Roundcube Webmail vulnerabilities
as exploited in the wild.
February 2026
Threat actors exploited CVE-2026-48842 in Roundcube, following the exploitation of previously disclosed vulnerabilities CVE-2025-49113 and CVE-2025-68461.
Click on any entity below to view its context and source!
attribution
CVE-2025-68461
Way back in February 2026, two other vulnerabilities in the same product (CVE-2025-49113 and CVE-2025-68461) were
tagged
as actively exploited by the U.S. Cybersecurity and Infrastructure Security Agency (CISA).
vulnerability
CVE-2025-49113
Way back in February 2026, two other vulnerabilities in the same product (CVE-2025-49113 and CVE-2025-68461) were
tagged
as actively exploited by the U.S. Cybersecurity and Infrastructure Security Agency (CISA).
May 2026
Roundcube released patches for the CVE-2026-48842 vulnerability in May 2026 as part of versions 1.6.16 and 1.7.1.
Click on any entity below to view its context and source!
infrastructure
Roundcube
Patches for the vulnerability were
released
by Roundcube in May 2026 as part of 1.6.16 and 1.7.1.
infrastructure
1.6.16
Patches for the vulnerability were
released
by Roundcube in May 2026 as part of 1.6.16 and 1.7.1.
infrastructure
1.7.1
Patches for the vulnerability were
released
by Roundcube in May 2026 as part of 1.6.16 and 1.7.1.
May 24, 2026
Roundcube released fixes for the CVE-2026-48842 vulnerability on May 24, 2026.
Click on any entity below to view its context and source!
infrastructure
Roundcube
Roundcube released the fixes on May 24, 2026.
July 2026
Threat actors dubbed UNK_MassTraction exploited known security flaws in Roundcube to deliver web shells or a post-exploitation tool called VShell.
Click on any entity below to view its context and source!
infrastructure
Roundcube
In July 2026, Proofpoint said it identified a suspected China-aligned adversary dubbed
UNK_MassTraction
exploiting known security flaws in Roundcube to deliver web shells or a post-exploitation tool called VShell.
source_region
China
In July 2026, Proofpoint said it identified a suspected China-aligned adversary dubbed
UNK_MassTraction
exploiting known security flaws in Roundcube to deliver web shells or a post-exploitation tool called VShell.
organisation
VShell
In July 2026, Proofpoint said it identified a suspected China-aligned adversary dubbed
UNK_MassTraction
exploiting known security flaws in Roundcube to deliver web shells or a post-exploitation tool called VShell.
September 21
The Canadian Centre for Cyber Security added a warning to its advisory on September 21 regarding the Roundcube SQL Injection CVE-2026-48842 vulnerability.
Click on any entity below to view its context and source!
organisation
the Canadian Centre for Cyber Security
The Canadian Centre for Cyber Security added the warning to its advisory on September 21, citing open-source reporting and urging administrators to apply the available updates.
September 23, 2026
Threat actors exploited a SQL injection vulnerability in Roundcube, affecting more than 523,000 internet-exposed instances.
Click on any entity below to view its context and source!
infrastructure
Roundcube
Data from the Shadowserver Foundation shows that there are
more than 523,000 Roundcube instances
exposed to the internet, with 10 of them
flagged
as vulnerable hosts as of September 23, 2026.
organisation
The Shadowserver Foundation
Data from the Shadowserver Foundation shows that there are
more than 523,000 Roundcube instances
exposed to the internet, with 10 of them
flagged
as vulnerable hosts as of September 23, 2026.
general_metric
523,000 Roundcube instances
Data from the Shadowserver Foundation shows that there are
more than 523,000 Roundcube instances
exposed to the internet, with 10 of them
flagged
as vulnerable hosts as of September 23, 2026.
general_metric
10 internet
Data from the Shadowserver Foundation shows that there are
more than 523,000 Roundcube instances
exposed to the internet, with 10 of them
flagged
as vulnerable hosts as of September 23, 2026.
Sep 25, 2026
Threat actors exploited the Roundcube SQL injection vulnerability CVE-2026-48842, which was publicly disclosed on September 25, 2026.
2026/09/25
The Canadian Centre for Cyber Security warned that a now-patched Roundcube Webmail vulnerability, tracked as CVE-2026-48842 with a CVSS score of 8.1, is being actively exploited in the wild by unauthenticated attackers who can inject SQL into Roundcube's database backend through the virtuser_query plugin.
Click on any entity below to view its context and source!
infrastructure
Roundcube
Roundcube Webmail Vulnerability in Attackers’ Crosshairs.
Threat actors have been exploiting a high-severity vulnerability in Roundcube, the popular open source webmail client, the Canadian Centre for Cyber Security warns.
Roundcube resolved the vulnerability in versions
1.6.16 and 1.7.1
, which were released in late May.
Data from the non-profit organization The Shadowserver Foundation
shows
that there are over 500,000 Roundcube servers accessible from the internet, but it is unclear how many of them are vulnerable.
Vulnerabilities in Roundcube servers are frequently targeted by threat actors.
In July, Proofpoint
reported
activity by a suspected China-nexus actor tracked as UNK_MassTraction, which exploited known Roundcube vulnerabilities to deploy web shells or VShell, a post-exploitation tool.
Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild.
A Roundcube Webmail vulnerability, tracked as CVE-2026-48842 (CVSS score of 8.1) and patched four months ago, is now being exploited in the wild.
The vulnerability CVE-2026-48842 affects Roundcube 1.6.x versions before 1.6.16 and 1.7.x versions before 1.7.1, but there’s an important detail: the vulnerable code sits in the
virtuser_query
plugin.
That gives an unauthenticated attacker a direct path to the database behind Roundcube.
This means an attacker does not need to authenticate to access the database behind Roundcube.
“Unauthenticated attackers can inject SQL into Roundcube’s database backend through the virtuser_query plugin, potentially exposing mail account credentials and stored messages.”
warns SentinelOne
.
Roundcube is an email application, and its database can contain information that becomes extremely useful once an attacker gets access to it.
Roundcube fixed the problem in May, but the exploitation warning arrived in September.
Threat actors have targeted multiple Roundcube flaws in attacks in the past.
In February, CISA listed
CVE-2025-49113
and
CVE-2025-68461
as actively exploited Roundcube vulnerabilities.
Roundcube has repeatedly appeared in attacks where a public-facing mail interface provides an initial point of access.
For defenders, the first step is to check which Roundcube versions are running.
However, this should not replace updating Roundcube.
Organizations with exposed Roundcube servers should therefore review application logs for signs of exploitation.
Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild.
Ravie Lakshmanan
Sep 25, 2026
Vulnerability / Email Security
The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild.
The vulnerability in question is
CVE-2026-48842
(CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.
"Unauthenticated attackers can inject SQL into Roundcube's database backend through the virtuser_query plugin, potentially exposing mail account credentials and stored messages," SentinelOne
said
.
Vulnerabilities in Roundcube have been an attractive target for threat actors looking to harvest sensitive email communications.
Roundcube security flaws have been a popular target for both cybercrime and state-backed hacking groups, with the Winter Vivern (TA473) Russian threat group exploiting a cross-site scripting (XSS) zero-day (CVE-2023-5631) in
attacks targeting European government entities
and the Russian APT28 cyber-espionage group abusing multiple flaws (CVE-2020-35730, CVE-2020-12641, and CVE-2021-44026)
to…
More recently, in February, the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
flagged two other Roundcube flaws
(CVE-2025-49113 and CVE-2025-68461) as actively exploited and ordered government agencies to secure their networks within three weeks.
Hackers now exploit critical Roundcube flaw in code injection attacks.
A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security.
Roundcube Webmail is a browser-based IMAP email client used as the default mail interface by thousands of services with millions of users, and it is pre-installed with the widely used cPanel web hosting control panel.
In May, the Roundcube security team
patched the flaw
(tracked as
CVE-2026-48842
), describing it as a pre-authenticated SQL injection in the virtuser_query built-in plugin, which handles database-driven user lookups and maps users to email addresses.
Successful exploitation can let threat actors with no privileges bypass authentication, inject and execute malicious database commands, and steal data from Roundcube's database in high-complexity attacks that don't require user interaction.
Roundcube also "strongly" recommended that users update their servers to versions 1.6.16 and 1.7.1, which address this vulnerability.
Threat monitoring non-profit Shadowserver
now tracks over 523,000 Roundcube instances
exposed on the Internet.
Roundcube instances exposed online
organisation
Roundcube Webmail Vulnerability
Roundcube Webmail Vulnerability in Attackers’ Crosshairs.
organisation
the Canadian Centre for Cyber Security
Threat actors have been exploiting a high-severity vulnerability in Roundcube, the popular open source webmail client, the Canadian Centre for Cyber Security warns.
Ravie Lakshmanan
Sep 25, 2026
Vulnerability / Email Security
The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild.
A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security.
infrastructure
1.6.16
Roundcube resolved the vulnerability in versions
1.6.16 and 1.7.1
, which were released in late May.
The vulnerability CVE-2026-48842 affects Roundcube 1.6.x versions before 1.6.16 and 1.7.x versions before 1.7.1, but there’s an important detail: the vulnerable code sits in the
virtuser_query
plugin.
The vulnerability in question is
CVE-2026-48842
(CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.
Roundcube also "strongly" recommended that users update their servers to versions 1.6.16 and 1.7.1, which address this vulnerability.
Versions older than 1.6.16 or 1.7.1 should be considered vulnerable.
infrastructure
1.7.1
Roundcube resolved the vulnerability in versions
1.6.16 and 1.7.1
, which were released in late May.
The vulnerability CVE-2026-48842 affects Roundcube 1.6.x versions before 1.6.16 and 1.7.x versions before 1.7.1, but there’s an important detail: the vulnerable code sits in the
virtuser_query
plugin.
The vulnerability in question is
CVE-2026-48842
(CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.
Roundcube also "strongly" recommended that users update their servers to versions 1.6.16 and 1.7.1, which address this vulnerability.
Versions older than 1.6.16 or 1.7.1 should be considered vulnerable.
organisation
The Shadowserver Foundation
Data from the non-profit organization The Shadowserver Foundation
shows
that there are over 500,000 Roundcube servers accessible from the internet, but it is unclear how many of them are vulnerable.
infrastructure
500,000 Roundcube servers
Data from the non-profit organization The Shadowserver Foundation
shows
that there are over 500,000 Roundcube servers accessible from the internet, but it is unclear how many of them are vulnerable.
organisation
VShell
In July, Proofpoint
reported
activity by a suspected China-nexus actor tracked as UNK_MassTraction, which exploited known Roundcube vulnerabilities to deploy web shells or VShell, a post-exploitation tool.
infrastructure
1.6
The vulnerability CVE-2026-48842 affects Roundcube 1.6.x versions before 1.6.16 and 1.7.x versions before 1.7.1, but there’s an important detail: the vulnerable code sits in the
virtuser_query
plugin.
The vulnerability in question is
CVE-2026-48842
(CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.
infrastructure
1.7
The vulnerability CVE-2026-48842 affects Roundcube 1.6.x versions before 1.6.16 and 1.7.x versions before 1.7.1, but there’s an important detail: the vulnerable code sits in the
virtuser_query
plugin.
The vulnerability in question is
CVE-2026-48842
(CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.
organisation
SentinelOne
“Unauthenticated attackers can inject SQL into Roundcube’s database backend through the virtuser_query plugin, potentially exposing mail account credentials and stored messages.”
warns SentinelOne
.
"Unauthenticated attackers can inject SQL into Roundcube's database backend through the virtuser_query plugin, potentially exposing mail account credentials and stored messages," SentinelOne
said
.
The attacker’s malicious input invokes the virtuser_query plugin to traverse the preg_replace() filter, resulting in quote characters being concatenated into an SQL string that is sent to the database, SentinelOne
explains
.
organisation
Vulnerability / Email Security
Ravie Lakshmanan
Sep 25, 2026
Vulnerability / Email Security
The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild.
organisation
SQL
The vulnerability in question is
CVE-2026-48842
(CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.
In May, the Roundcube security team
patched the flaw
(tracked as
CVE-2026-48842
), describing it as a pre-authenticated SQL injection in the virtuser_query built-in plugin, which handles database-driven user lookups and maps users to email addresses.
Tracked as CVE-2026-48842 (CVSS score of 8.1), the security defect is described as an SQL injection in the
virtuser_query
plugin that can be exploited without authentication.
The bug is a pre-authentication SQL injection.
infrastructure
8.1
The vulnerability in question is
CVE-2026-48842
(CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.
threat_actor
Winter Vivern
Roundcube security flaws have been a popular target for both cybercrime and state-backed hacking groups, with the Winter Vivern (TA473) Russian threat group exploiting a cross-site scripting (XSS) zero-day (CVE-2023-5631) in
attacks targeting European government entities
and the Russian APT28 cyber-espionage group abusing multiple flaws (CVE-2020-35730, CVE-2020-12641, and CVE-2021-44026)
to…
organisation
IMAP
Roundcube Webmail is a browser-based IMAP email client used as the default mail interface by thousands of services with millions of users, and it is pre-installed with the widely used cPanel web hosting control panel.
organisation
cPanel
Roundcube Webmail is a browser-based IMAP email client used as the default mail interface by thousands of services with millions of users, and it is pre-installed with the widely used cPanel web hosting control panel.
organisation
the Cyber Centre
“Open-source reporting indicates that CVE-2026-48842 is being exploited in the wild,” the Cyber Centre said.
In an update shared this week, the Cyber Centre
said
the security flaw is being actively exploited in the wild, citing open-source reporting.
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, CVE-2026-48842)
organisation
CVE-2025
Some examples include
CVE-2025-68461
,
CVE-2025-49113
, and
CVE-2024-37383
.
organisation
AEM Forms
Adobe Patches Critical Flaws in Connect, AEM Forms
Related:
Check Point Patches Exploited Management Server Zero-Day
organisation
PHP
The plugin performs database lookups that map email addresses to mailbox usernames and uses PHP’s
preg_replace()
function with backslash escaping to try to prevent SQL injection.
threat_actor
APT28
…r target for both cybercrime and state-backed hacking groups, with the Winter Vivern (TA473) Russian threat group exploiting a cross-site scripting (XSS) zero-day (CVE-2023-5631) in
attacks targeting European government entities
and the Russian APT28 cyber-espionage group abusing multiple flaws (CVE-2020-35730, CVE-2020-12641, and CVE-2021-44026)
to breach Ukrainian government email systems
.
organisation
NFL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
September 28, 2026
Threat actors are exploiting the Roundcube SQL injection CVE-2026-48842 vulnerability, which remains unpatched in webmail servers.
Click on any entity below to view its context and source!
infrastructure
Roundcube
Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild
Pierluigi Paganini
September 28, 2026
Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild, putting unpatched webmail servers at risk of database compromise.
vulnerability
CVE-2026-48842
Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild
Pierluigi Paganini
September 28, 2026
Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild, putting unpatched webmail servers at risk of database compromise.
Tactical Metrics
Metrics
infrastructure
Roundcube
Affected Product
Click for context!
Roundcube Webmail Vulnerability in Attackers’ Crosshairs.
Threat actors have been exploiting a high-severity vulnerability in Roundcube, the popular open source webmail client, the Canadian Centre for Cyber Security warns.
Roundcube resolved the vulnerability in versions
1.6.16 and 1.7.1
, which were released in late May.
Data from the non-profit organization The Shadowserver Foundation
shows
that there are over 500,000 Roundcube servers accessible from the internet, but it is unclear how many of them are vulnerable.
Vulnerabilities in Roundcube servers are frequently targeted by threat actors.
In July, Proofpoint
reported
activity by a suspected China-nexus actor tracked as UNK_MassTraction, which exploited known Roundcube vulnerabilities to deploy web shells or VShell, a post-exploitation tool.
Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild.
Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild
Pierluigi Paganini
September 28, 2026
Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild, putting unpatched webmail servers at risk of database compromise.
A Roundcube Webmail vulnerability, tracked as CVE-2026-48842 (CVSS score of 8.1) and patched four months ago, is now being exploited in the wild.
The vulnerability CVE-2026-48842 affects Roundcube 1.6.x versions before 1.6.16 and 1.7.x versions before 1.7.1, but there’s an important detail: the vulnerable code sits in the
virtuser_query
plugin.
Roundcube released the fixes on May 24, 2026.
That gives an unauthenticated attacker a direct path to the database behind Roundcube.
This means an attacker does not need to authenticate to access the database behind Roundcube.
“Unauthenticated attackers can inject SQL into Roundcube’s database backend through the virtuser_query plugin, potentially exposing mail account credentials and stored messages.”
warns SentinelOne
.
Roundcube is an email application, and its database can contain information that becomes extremely useful once an attacker gets access to it.
Roundcube fixed the problem in May, but the exploitation warning arrived in September.
Threat actors have targeted multiple Roundcube flaws in attacks in the past.
In February, CISA listed
CVE-2025-49113
and
CVE-2025-68461
as actively exploited Roundcube vulnerabilities.
Roundcube has repeatedly appeared in attacks where a public-facing mail interface provides an initial point of access.
For defenders, the first step is to check which Roundcube versions are running.
However, this should not replace updating Roundcube.
Organizations with exposed Roundcube servers should therefore review application logs for signs of exploitation.
In July 2026, Proofpoint said it identified a suspected China-aligned adversary dubbed
UNK_MassTraction
exploiting known security flaws in Roundcube to deliver web shells or a post-exploitation tool called VShell.
Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild.
Ravie Lakshmanan
Sep 25, 2026
Vulnerability / Email Security
The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild.
The vulnerability in question is
CVE-2026-48842
(CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.
"Unauthenticated attackers can inject SQL into Roundcube's database backend through the virtuser_query plugin, potentially exposing mail account credentials and stored messages," SentinelOne
said
.
Patches for the vulnerability were
released
by Roundcube in May 2026 as part of 1.6.16 and 1.7.1.
Data from the Shadowserver Foundation shows that there are
more than 523,000 Roundcube instances
exposed to the internet, with 10 of them
flagged
as vulnerable hosts as of September 23, 2026.
Vulnerabilities in Roundcube have been an attractive target for threat actors looking to harvest sensitive email communications.
Roundcube security flaws have been a popular target for both cybercrime and state-backed hacking groups, with the Winter Vivern (TA473) Russian threat group exploiting a cross-site scripting (XSS) zero-day (CVE-2023-5631) in
attacks targeting European government entities
and the Russian APT28 cyber-espionage group abusing multiple flaws (CVE-2020-35730, CVE-2020-12641, and CVE-2021-44026)
to…
More recently, in February, the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
flagged two other Roundcube flaws
(CVE-2025-49113 and CVE-2025-68461) as actively exploited and ordered government agencies to secure their networks within three weeks.
Hackers now exploit critical Roundcube flaw in code injection attacks.
A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security.
Roundcube Webmail is a browser-based IMAP email client used as the default mail interface by thousands of services with millions of users, and it is pre-installed with the widely used cPanel web hosting control panel.
In May, the Roundcube security team
patched the flaw
(tracked as
CVE-2026-48842
), describing it as a pre-authenticated SQL injection in the virtuser_query built-in plugin, which handles database-driven user lookups and maps users to email addresses.
Successful exploitation can let threat actors with no privileges bypass authentication, inject and execute malicious database commands, and steal data from Roundcube's database in high-complexity attacks that don't require user interaction.
Roundcube also "strongly" recommended that users update their servers to versions 1.6.16 and 1.7.1, which address this vulnerability.
Threat monitoring non-profit Shadowserver
now tracks over 523,000 Roundcube instances
exposed on the Internet.
Roundcube instances exposed online
Since May 2022, the cybersecurity agency
has tagged 11 Roundcube Webmail vulnerabilities
as exploited in the wild.
Metrics
infrastructure
1.6.16
Software Version
Roundcube resolved the vulnerability in versions
1.6.16 and 1.7.1
, which were released in late May.
The vulnerability CVE-2026-48842 affects Roundcube 1.6.x versions before 1.6.16 and 1.7.x versions before 1.7.1, but there’s an important detail: the vulnerable code sits in the
virtuser_query
plugin.
Versions older than 1.6.16 or 1.7.1 should be considered vulnerable.
The vulnerability in question is
CVE-2026-48842
(CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.
Patches for the vulnerability were
released
by Roundcube in May 2026 as part of 1.6.16 and 1.7.1.
Roundcube also "strongly" recommended that users update their servers to versions 1.6.16 and 1.7.1, which address this vulnerability.
Metrics
infrastructure
1.7.1
Software Version
Roundcube resolved the vulnerability in versions
1.6.16 and 1.7.1
, which were released in late May.
The vulnerability CVE-2026-48842 affects Roundcube 1.6.x versions before 1.6.16 and 1.7.x versions before 1.7.1, but there’s an important detail: the vulnerable code sits in the
virtuser_query
plugin.
Versions older than 1.6.16 or 1.7.1 should be considered vulnerable.
The vulnerability in question is
CVE-2026-48842
(CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.
Patches for the vulnerability were
released
by Roundcube in May 2026 as part of 1.6.16 and 1.7.1.
Roundcube also "strongly" recommended that users update their servers to versions 1.6.16 and 1.7.1, which address this vulnerability.
Metrics
infrastructure
500,000
Roundcube Servers
Data from the non-profit organization The Shadowserver Foundation
shows
that there are over 500,000 Roundcube servers accessible from the internet, but it is unclear how many of them are vulnerable.
Metrics
infrastructure
1.6
Software Version
The vulnerability CVE-2026-48842 affects Roundcube 1.6.x versions before 1.6.16 and 1.7.x versions before 1.7.1, but there’s an important detail: the vulnerable code sits in the
virtuser_query
plugin.
The vulnerability in question is
CVE-2026-48842
(CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.
Metrics
infrastructure
1.7
Software Version
The vulnerability CVE-2026-48842 affects Roundcube 1.6.x versions before 1.6.16 and 1.7.x versions before 1.7.1, but there’s an important detail: the vulnerable code sits in the
virtuser_query
plugin.
The vulnerability in question is
CVE-2026-48842
(CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.
Metrics
infrastructure
8.1
Software Version
The vulnerability in question is
CVE-2026-48842
(CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.
Intelligence Sources
BleepingComputer
2026-09-24
Security Affairs
2026-09-28
SecurityWeek
2026-09-25
The Hacker News
2026-09-25
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T06:34
Comprehensive Tactical Telemetry
Highly Correlated Entities
16x
organisation
Identified Entity
Roundcube Webmail Vulnerability
entity
10x
timeline
Temporal Reference
September 28, 2026
date
8x
vulnerability
Exploited CVE
CVE-2026-48842
cve
5x
infrastructure
Software Version
1.6.16
version
5x
attribution
Attributing Entity
CISA
authority
2x
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
2x
source region
Origin Country
China
country
2x
target region
Target Country
Canada
country
2x
threat actor
APT Group
Winter Vivern
actor
Contextual Telemetry
Context Block
10 METRICS
infrastructure
Affected Product
Roundcube
software
vulnerability
CVSS Score
8
score
infrastructure
Roundcube Servers
500,000
roundcube servers
general metric
Sep
25
sep
general metric
Score
8
score
general metric
Roundcube Instances
523,000
roundcube instances
general metric
Internet
10
internet
industry
Targeted Sector
Government
sector
tactic
Cyber Operation Type
Espionage
tactic
general metric
Roundcube Webmail
11
roundcube webmail
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.