A high-severity security vulnerability in Roundcube Webmail that was patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security.
Tracked as CVE-2026-48842, the flaw is a pre-authentication SQL injection vulnerability in Roundcube’s built-in virtuser_query plugin. The plugin handles database-based user lookups and maps users to email addresses. Roundcube patched the vulnerability in May with releases 1.6.16 and 1.7.1.
Successful exploitation can allow attackers without any privileges to bypass authentication and inject or execute malicious database commands. The attacks can also be used to steal information stored in Roundcube databases and do not require interaction from the targeted user.
Roundcube strongly recommends that administrators update their installations to versions 1.6.16 or 1.7.1. Shadowserver currently tracks more than 523,000 Roundcube instances exposed to the internet, although it is not known how many of those systems have already been patched or are honeypots.



