Years-old Roundcube webmail flaw now under active exploitation, Canadian cyber agency warns

· CyberSecurity

A high-severity Roundcube webmail flaw patched back in May is now being actively exploited, Canada's Centre for Cyber Security warned this week, updating its original advisory after open-source reporting showed real-world attacks1. CVE-2026-48842 is a pre-authenticated SQL injection in Roundcube's virtuser_query plugin, letting an attacker bypass authentication and run malicious database commands to steal data without needing to trick a user into anything, though the attack itself is technically complex1.

Roundcube fixed the flaw in versions 1.6.16 and 1.7.1 back in May, but adoption has clearly lagged: Shadowserver currently tracks more than 523,000 internet-exposed Roundcube instances, though it is unclear how many remain unpatched versus already updated or run as honeypots1.

Why it matters: a four-month gap between patch and confirmed exploitation is a familiar pattern for widely deployed, self-hosted webmail software, and with over half a million instances exposed, unpatched Roundcube servers make an easy target for anyone scanning for the flaw.

Sources

  1. Hackers now exploit critical Roundcube flaw in code injection attacks (BleepingComputer)