Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: self-hosted-email (1 article)Clear

Critical Roundcube webmail SQL injection now actively exploited to bypass authentication and steal data

The Canadian Centre for Cyber Security updated its May advisory to warn that attackers are now actively exploiting a Roundcube Webmail flaw, CVE-2026-48842, four months after it was patched. Roundcube is a browser-based IMAP client used as the default mail interface by thousands of services and pre-installed with the cPanel hosting control panel. The flaw is a pre-authenticated SQL injection in the virtuser_query plugin that handles database-driven user lookups. Exploitation lets an unprivileged attacker bypass authentication, inject and run database commands, and steal data from Roundcube's database, without user interaction in high-complexity attacks. Roundcube fixed it in versions 1.6.16 and 1.7.1, and Shadowserver tracks over 523,000 exposed instances online.

Check
Inventory internet-facing Roundcube instances, including those bundled with cPanel, and upgrade to 1.6.16 or 1.7.1 immediately while checking for signs of compromise.
Affected
Unpatched Roundcube servers let an unauthenticated attacker exploit the virtuser_query SQL injection to bypass login and read the webmail database.
Fix
Update Roundcube to 1.6.16 or 1.7.1, restrict webmail exposure, and review database and authentication logs for injection attempts.