Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild
Roundcube pre-auth SQL injection CVE-2026-48842 is being exploited, Canadian cyber authorities warned.
The Canadian Centre for Cyber Security warned that CVE-2026-48842, a pre-authentication SQL injection in Roundcube Webmail's virtuser_query plugin, is being actively exploited. The CVSS 8.1 bug affects 1.6.x before 1.6.16 and 1.7.x before 1.7.1 and comes from a preg_replace() backslash escape bypass that lets unauthenticated attackers inject SQL, potentially exposing mail credentials and stored messages. Roundcube patched it in May 2026. Shadowserver counted more than 523,000 internet-exposed Roundcube instances, with 10 flagged vulnerable as of September 23, 2026. Prior exploited Roundcube flaws include CVE-2025-49113 and CVE-2025-68461.