Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: webmail (2 articles)Clear

Critical Roundcube webmail SQL injection now actively exploited to bypass authentication and steal data

The Canadian Centre for Cyber Security updated its May advisory to warn that attackers are now actively exploiting a Roundcube Webmail flaw, CVE-2026-48842, four months after it was patched. Roundcube is a browser-based IMAP client used as the default mail interface by thousands of services and pre-installed with the cPanel hosting control panel. The flaw is a pre-authenticated SQL injection in the virtuser_query plugin that handles database-driven user lookups. Exploitation lets an unprivileged attacker bypass authentication, inject and run database commands, and steal data from Roundcube's database, without user interaction in high-complexity attacks. Roundcube fixed it in versions 1.6.16 and 1.7.1, and Shadowserver tracks over 523,000 exposed instances online.

Check
Inventory internet-facing Roundcube instances, including those bundled with cPanel, and upgrade to 1.6.16 or 1.7.1 immediately while checking for signs of compromise.
Affected
Unpatched Roundcube servers let an unauthenticated attacker exploit the virtuser_query SQL injection to bypass login and read the webmail database.
Fix
Update Roundcube to 1.6.16 or 1.7.1, restrict webmail exposure, and review database and authentication logs for injection attempts.

Zimbra patches critical flaw letting a crafted email run code in your session

Zimbra is urging customers to update after fixing a critical stored cross-site scripting flaw in the Classic Web Client of its widely used email and collaboration platform. A specially crafted email can run malicious scripts when it is simply opened, potentially exposing mailbox contents, session data, and account settings, and enabling session hijacking or credential theft. The flaw, reported by Google's Threat Analysis Group, has no CVE assigned yet and is not confirmed as exploited, but the group often surfaces bugs used by state-backed actors. Zimbra's web client has been a repeated target: Russian-linked groups have exploited similar cross-site scripting flaws against government and military organizations. Updating to version 10.1.19 fixes it.

Check
Identify Zimbra Collaboration servers using the Classic Web Client, confirm their versions, and prioritize updating any that are internet-facing or serve high-value users such as executives and administrators.
Affected
Organizations running Zimbra Collaboration's Classic Web Client before version 10.1.19; an attacker can run code in a victim's session by sending an email the victim opens, risking mailbox and credential theft.
Fix
Update Zimbra Collaboration to version 10.1.19 promptly, given the platform's history of state-actor exploitation, and consider moving users to the modern web client and monitoring for suspicious email-borne scripts.