The Canadian Centre for Cyber Security says CVE-2026-48842 (CVSS 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail, is being exploited in the wild, citing open-source reporting and disclosing no further detail about the activity. The flaw affects versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1, and stems from a preg_replace() backslash-escape bypass that allows unauthenticated attackers to inject arbitrary SQL into Roundcube's database backend — potentially exposing mail account credentials and stored messages. Roundcube released the patches in May 2026; Shadowserver Foundation data shows more than 523,000 Roundcube instances exposed to the internet, with up to 10 flagged as vulnerable hosts as of 23 September. Exploitation of the webmail platform is a well-trodden path — Proofpoint linked a suspected China-aligned actor to Roundcube flaws in July 2026, and two earlier Roundcube vulnerabilities were added to CISA's catalog in February 2026. The advisory's value is the reminder that mail infrastructure tends to be patched on a slower cadence than its exposure profile warrants.
| Attribute | Detail |
|---|---|
| Sector | Global (Macro) |
| Date | 2026-09-27 |
| Source | The Hacker News |
| Reliability | Tier 2 |
| CVEs | CVE-2026-48842 |