Risk actors have been exploiting a high-severity vulnerability in Roundcube, the favored open supply webmail shopper, the Canadian Centre for Cyber Safety warns.
Tracked as CVE-2026-48842 (CVSS rating of 8.1), the safety defect is described as an SQL injection within the virtuser_query plugin that may be exploited with out authentication.
The plugin resolves e-mail addresses to mailbox usernames and makes use of the preg_replace() filter with backslash escaping to neutralize injection makes an attempt.
CVE-2026-48842, nevertheless, permits attackers to bypass the safety through the use of crafted queries containing backslash sequences that defeat the plugin’s regular-expression escaping mechanism.
The attacker’s malicious enter invokes the virtuser_query plugin to traverse the preg_replace() filter, leading to quote characters being concatenated into an SQL string that’s despatched to the database, SentinelOne explains.
Roundcube resolved the vulnerability in variations 1.6.16 and 1.7.1, which had been launched in late Could.
This week, the Canadian Centre for Cyber Safety warned that menace actors have been exploiting it in assaults, however didn’t share particulars on the noticed exploitation.
“Open-source reporting signifies that CVE-2026-48842 is being exploited within the wild,” the Cyber Centre mentioned.
As Paymob data safety lead Omar Ahmed factors out, profitable exploitation of the bug permits attackers to tamper with database operations, entry protected data, entry consumer identities, messages, and tackle books, and map authentication workflows and admin capabilities.
Knowledge from the non-profit group The Shadowserver Basis reveals that there are over 500,000 Roundcube servers accessible from the web, however it’s unclear what number of of them are weak.
Vulnerabilities in Roundcube servers are continuously focused by menace actors. Some examples embrace CVE-2025-68461, CVE-2025-49113, and CVE-2024-37383.
Associated: SolarWinds Patches Essential RCE Flaws in Observability Self-Hosted
Associated: Essential WordPress Vulnerability Exploited Instantly After Disclosure
Associated: Adobe Patches Essential Flaws in Join, AEM Kinds
Associated: Test Level Patches Exploited Administration Server Zero-Day









