INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Roundcube Webmail Vulnerability Exploited in the Wild via SQL Injection

| 2026-09-25 06:57 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
A critical vulnerability in Roundcube webmail has been exploited in the wild, putting over 500,000 servers at risk of database compromise. The vulnerability, tracked as CVE-2026-48842, affects versions before 1.6.16 and 1.7.1, with a CVSS score of 8.1. An unauthenticated attacker can inject SQL into the virtuser_query plugin, potentially exposing mail account credentials and stored messages. This exploit is particularly concerning as it allows an attacker to access the database without authentication. The vulnerability was patched four months ago on May 24, 2026, but its exploitation in the wild highlights a need for increased vigilance among organizations using Roundcube webmail.
Technical Mitigations AI-generated
• Implement input validation and sanitization for the virtuser_query plugin to prevent SQL injection attacks. • Use prepared statements or parameterized queries instead of string-based SQL queries to reduce the risk of SQL injection vulnerabilities. • Regularly update and patch Roundcube versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1, as well as ensure that all plugins are up-to-date, especially the virtuser_query plugin.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Winter VivernWinter VivernAPT28APT28 CVE-2026-48842CVE-2026-48842 CVE-2025-68461CVE-2025-68461 CVE-2020-35730CVE-2020-35730 CVE-2024-37383CVE-2024-37383 CVE-2025-49113CVE-2025-49113 CVE-2021-44026CVE-2021-44026 CVE-2023-5631CVE-2023-5631 CVE-2020-12641CVE-2020-12641
Target & Sectors
NORTH_AMERICA NORTH_AMERICA governmentgovernment
Incident Timeline
‎May 2022
Threat actors have exploited 11 previously tagged Roundcube Webmail vulnerabilities, CVE-2026-48842 being one of them, since May 2022.
infrastructure Roundcube
general_metric 11 Roundcube Webmail
‎February 2026
Threat actors exploited CVE-2026-48842 in Roundcube, following the exploitation of previously disclosed vulnerabilities CVE-2025-49113 and CVE-2025-68461.
attribution CVE-2025-68461
vulnerability CVE-2025-49113
‎May 2026
Roundcube released patches for the CVE-2026-48842 vulnerability in May 2026 as part of versions 1.6.16 and 1.7.1.
infrastructure Roundcube
infrastructure 1.6.16
infrastructure 1.7.1
‎May 24, 2026
Roundcube released fixes for the CVE-2026-48842 vulnerability on May 24, 2026.
infrastructure Roundcube
‎July 2026
Threat actors dubbed UNK_MassTraction exploited known security flaws in Roundcube to deliver web shells or a post-exploitation tool called VShell.
infrastructure Roundcube
source_region China
organisation VShell
‎September 21
The Canadian Centre for Cyber Security added a warning to its advisory on September 21 regarding the Roundcube SQL Injection CVE-2026-48842 vulnerability.
organisation the Canadian Centre for Cyber Security
‎September 23, 2026
Threat actors exploited a SQL injection vulnerability in Roundcube, affecting more than 523,000 internet-exposed instances.
infrastructure Roundcube
organisation The Shadowserver Foundation
general_metric 523,000 Roundcube instances
general_metric 10 internet
‎Sep 25, 2026
Threat actors exploited the Roundcube SQL injection vulnerability CVE-2026-48842, which was publicly disclosed on September 25, 2026.
‎2026/09/25
The Canadian Centre for Cyber Security warned that a now-patched Roundcube Webmail vulnerability, tracked as CVE-2026-48842 with a CVSS score of 8.1, is being actively exploited in the wild by unauthenticated attackers who can inject SQL into Roundcube's database backend through the virtuser_query plugin.
infrastructure Roundcube
organisation Roundcube Webmail Vulnerability
organisation the Canadian Centre for Cyber Security
infrastructure 1.6.16
infrastructure 1.7.1
organisation The Shadowserver Foundation
infrastructure 500,000 Roundcube servers
organisation VShell
infrastructure 1.6
infrastructure 1.7
organisation SentinelOne
organisation Vulnerability / Email Security
organisation SQL
infrastructure 8.1
threat_actor Winter Vivern
organisation IMAP
organisation cPanel
organisation the Cyber Centre
organisation SecurityAffairs
organisation CVE-2025
organisation AEM Forms
organisation PHP
threat_actor APT28
organisation NFL
organisation CHANEL
‎September 28, 2026
Threat actors are exploiting the Roundcube SQL injection CVE-2026-48842 vulnerability, which remains unpatched in webmail servers.
infrastructure Roundcube
vulnerability CVE-2026-48842
Tactical Metrics
Metrics
infrastructure
‎Roundcube
Affected Product
Metrics
infrastructure
‎1.6.16
Software Version
Metrics
infrastructure
‎1.7.1
Software Version
Metrics
infrastructure
500,000
Roundcube Servers
Metrics
infrastructure
‎1.6
Software Version
Metrics
infrastructure
‎1.7
Software Version
Metrics
infrastructure
‎8.1
Software Version
Intelligence Sources