Actively Exploited Roundcube Webmail Flaw Puts Email Credentials at Risk
The Canadian Centre for Cyber Security has warned that a now-patched vulnerability in Roundcube Webmail, tracked as CVE-2026-48842 (CVSS 8.1), is being actively exploited. The flaw is a pre-authentication SQL injection in the software's virtuser_query plugin, affecting Roundcube versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1. It allows attackers to inject SQL commands into the database without needing to log in, potentially exposing mail account credentials and stored messages.
Roundcube released patches for the issue in May 2026 with versions 1.6.16 and 1.7.1. Despite this, the Cyber Centre confirmed active exploitation this week based on open-source reporting, though further technical details have not been released. Shadowserver Foundation data shows more than 523,000 Roundcube instances are exposed to the internet, with a small number already flagged as vulnerable.
Roundcube has been a recurring target for attackers seeking access to email communications. Earlier in 2026, a suspected China-aligned group known as UNK_MassTraction was observed exploiting Roundcube flaws to deploy web shells and a post-exploitation tool called VShell, while separate vulnerabilities were flagged by US authorities as actively exploited in February 2026.