Active Exploitation Reported for Roundcube Pre-Auth SQL Injection

The Canadian Centre for Cyber Security has warned that attackers are actively exploiting CVE-2026-48842, a pre-authentication SQL injection vulnerability in Roundcube Webmail. The flaw has a CVSS score of 8.1 and affects Roundcube 1.6.x releases before 1.6.16 and 1.7.x releases before 1.7.1.
Roundcube released patches in May 2026 through versions 1.6.16 and 1.7.1. In its latest update, the Cyber Centre said exploitation had been observed in the wild, citing open-source reporting. It did not publish additional technical or operational details about the activity.
How the Roundcube flaw works
The issue is located in the virtuser_query plugin. A bypass involving backslash escaping in preg_replace() can allow an unauthenticated attacker to inject arbitrary SQL statements into the Roundcube database backend.
SentinelOne said the resulting database access could potentially expose mail account credentials and stored messages. Because the attack does not require authentication, organisations should treat internet-facing instances running the affected versions as a priority for verification and remediation.
Exposure remains substantial
Shadowserver Foundation data showed more than 523,000 Roundcube instances exposed to the internet. As of September 23, 2026, 10 hosts were flagged as vulnerable. The exposed-instance total is not a count of vulnerable systems, but it illustrates the scale of the deployment base that administrators may need to review.
Roundcube has remained a target for actors seeking access to sensitive email communications. In July 2026, Proofpoint said a suspected China-aligned adversary it tracks as UNK_MassTraction had exploited known Roundcube flaws to deploy web shells or the post-exploitation tool VShell.
Two other Roundcube vulnerabilities, CVE-2025-49113 and CVE-2025-68461, were added to CISA’s actively exploited catalogue in February 2026. That history, combined with the current warning, makes version validation important even where teams believe past patching has been completed.
What businesses should do
Administrators should inventory Roundcube deployments, determine whether the virtuser_query plugin is in use, and confirm that affected 1.6.x systems are updated to 1.6.16 or later and affected 1.7.x systems to 1.7.1 or later. Organisations should also review systems that were exposed while unpatched for signs requiring their established incident-response process.
The practical business implication is straightforward: teams responsible for email services should prioritise patch verification for exposed Roundcube systems because an unauthenticated SQL injection now has publicly reported active exploitation.

