Roundcube security advisory (AV26-503) – Update 1
Canada's Cyber Centre says CVE-2026-48842 in Roundcube Webmail is exploited and urges patching.
The Canadian Centre for Cyber Security updated advisory AV26-503 on Roundcube Webmail vulnerabilities affecting versions before 1.6.16 and 1.7.1. The September 21, 2026 update says open-source reporting indicates CVE-2026-48842 is being exploited in the wild. The Cyber Centre urges users and administrators to review the linked advisories and install the fixes. The notice does not describe the vulnerability's impact or attack method.
- CVE-2026-48842 in Roundcube Webmail is reportedly exploited in the wild.
- Vulnerable versions are those before 1.6.16 and before 1.7.1.
- Canada's Cyber Centre urges administrators to review links and patch.
Vulnerabilities mentionedAll →
- CVE-2026-488428.1<1%Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash…published PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-48842 | Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash… |
Full article82 words · extracted from cyber.gc.ca · click to collapse
Serial number: AV26-503
Date: May 25, 2026
Updated: September 21, 2026
On May 24, 2026, Roundcube published security advisories to address vulnerabilities in the following product:
- Roundcube Webmail – versions prior to 1.6.16
- Roundcube Webmail – versions prior to 1.7.1
Update 1
Open-source reporting indicates that CVE-2026-48842 is being exploited in the wild.
The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/roundcube-security-advisory-av26-503