Roundcube Webmail Vulnerability CVE-2026-48842 Actively Exploited: Update Now
Attackers are actively exploiting a high-severity vulnerability in Roundcube Webmail that was patched in May, according to the Canadian Centre for Cyber Security.
Roundcube is a browser-based IMAP email client used as the default webmail interface by thousands of services and millions of users. It is also included with the widely used cPanel web hosting control panel.
Roundcube CVE-2026-48842 vulnerability explained
In May, the Roundcube security team fixed CVE-2026-48842, a pre-authentication SQL injection flaw in the built-in virtuser_query plugin.
The plugin handles database-driven user lookups and maps users to email addresses. Because the flaw can be exploited before authentication, an attacker does not need valid credentials to target a vulnerable server.
A successful attack could allow an unprivileged attacker to bypass authentication, inject and execute malicious database commands, and steal data from a Roundcube database. The attack is considered complex but does not require user interaction.
Roundcube strongly recommends that administrators upgrade their servers to version 1.6.16 or 1.7.1, which address the vulnerability.
More than 523,000 Roundcube instances exposed online
Nonprofit threat-monitoring organization Shadowserver is currently tracking more than 523,000 Roundcube instances exposed to the internet.
However, it is not known how many of those systems are honeypots or how many have already been patched against CVE-2026-48842.

Canadian Cyber Security Centre confirms active exploitation
On Monday, four months after CVE-2026-48842 was patched, the Canadian Centre for Cyber Security updated its May advisory to warn that attackers are actively exploiting the Roundcube vulnerability.
“Open source reports indicate that CVE-2026-48842 is being exploited in the wild,” the Cyber Centre warned, urging administrators to secure their webmail servers.
How to protect vulnerable Roundcube servers
Administrators should apply the available security updates as soon as possible and upgrade to Roundcube 1.6.16 or 1.7.1.
Administrators who cannot immediately upgrade should disable or remove the virtuser_query plugin to eliminate the attack vector. This is a temporary mitigation and should not replace installing the security updates.
Roundcube remains a target for hackers
Roundcube security flaws have made the platform a popular target for both cybercrime and state-sponsored hacking groups.
Russian threat group Winter Vivern, also known as TA473, previously targeted European government agencies by exploiting a Roundcube cross-site scripting zero-day vulnerability, CVE-2023-5631.
Russian APT28 has also exploited multiple Roundcube vulnerabilities, including CVE-2020-35730, CVE-2020-12641, and CVE-2021-44026, to compromise Ukrainian government email systems.
More recently, in February, the US Cybersecurity and Infrastructure Security Agency reported that two other Roundcube flaws, CVE-2025-49113 and CVE-2025-68461, were being actively exploited. CISA ordered government agencies to secure their networks within three weeks.
Since May 2022, CISA has added 11 Roundcube Webmail vulnerabilities to its Known Exploited Vulnerabilities catalog.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a two-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



