Roundcube CVE-2026-48842 Under Active Exploitation: Pre-Auth SQL Injection Threatens 523,000 Exposed Webmail Instances
Roundcube CVE-2026-48842 Under Active Exploitation: Pre-Auth SQL Injection Threatens 523,000 Exposed Webmail Instances
The Canadian Centre for Cyber Security has confirmed that CVE-2026-48842, a pre-authentication SQL injection in Roundcube Webmail, is actively exploited in the wild. The flaw, rated CVSS 8.1, sits in the virtuser_query plugin and affects Roundcube 1.6.x versions before 1.6.16 and 1.7.x versions before 1.7.1. Both patched releases shipped in May 2026 — but roughly four months later, the Cyber Centre updated its advisory on Monday, citing open-source reporting, to warn that attackers are now going after unpatched installations.
The root cause is a preg_replace() backslash escape bypass that allows arbitrary SQL statements to be injected without any authentication. "Unauthenticated attackers can inject SQL into Roundcube's database backend through the virtuser_query plugin, potentially exposing mail account credentials and stored messages," SentinelOne said in a technical note on the flaw. Successful exploitation can bypass authentication, inject and execute malicious database commands, and steal data from the Roundcube database in attacks that require no user interaction.
The exposure is enormous. The Shadowserver Foundation tracks more than 523,000 Roundcube instances exposed to the internet, ten of them flagged as vulnerable hosts as of September 23, 2026. Roundcube is a browser-based IMAP client used as the default mail interface by thousands of hosting services, and it is pre-installed with the widely used cPanel hosting control panel — which means many admins are running it without ever having chosen to deploy it.
Roundcube has long been a favorite target of both criminals and state-backed groups. In July 2026, Proofpoint described a suspected China-aligned adversary it calls UNK_MassTraction exploiting known Roundcube flaws to deliver web shells and the VShell post-exploitation tool. The Russian Winter Vivern group (TA473) abused an XSS zero-day (CVE-2023-5631) against European government targets, and APT28 chained three older flaws against Ukrainian government email systems. In February 2026, CISA flagged CVE-2025-49113 and CVE-2025-68461 as actively exploited, and the agency has now tagged 11 Roundcube vulnerabilities as exploited in the wild since May 2022.
What Should You Do?
- Update immediately to Roundcube 1.6.16 (1.6 LTS) or 1.7.1. The patch has been available for four months and attackers are explicitly hunting the unpatched long tail.
- Cannot upgrade right away? Disable or remove the virtuser_query plugin — Roundcube itself recommends this as the way to eliminate the attack vector while you plan the update.
- Inventory your webmail perimeter. Between cPanel defaults and forgotten hosting deployments, many organizations run exposed Roundcube instances nobody maintains. Check Shadowserver-style exposure data for your domains.
- Treat the database as exposed. If your instance ran a vulnerable version, review it for suspicious queries and unexpected records, and rotate mail account credentials that could have been read from the database.
The WAF Angle
Pre-auth SQL injection is the flaw class WAFs were built for — but context is what defeats generic rules. The malicious SQL rides through a plugin endpoint that rule sets may treat as a legitimate lookup path, and virtual-user queries look like ordinary database traffic. Default SQLi signatures will catch the obvious payloads, but a backslash-escape bypass is exactly the kind of syntax variation that slips past pattern matching. The practical move is to put webmail behind a WAF with SQLi detection tuned to the virtuser path, rate-limit unauthenticated plugin endpoints, and remember that mail interfaces are crown-jewel attack surfaces: eleven exploited-in-the-wild flaws in one product since 2022 all point at the same conclusion — attackers prefer the webmail login page, because behind it sits every message the organization has ever sent.