Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

Attackers Exploit Critical Roundcube Webmail Flaw

Attackers are actively exploiting a high-severity vulnerability in Roundcube Webmail that was patched in May, according to the Canadian Centre for Cyber Security. The centre updated its advisory on Monday, citing open-source reporting that the flaw is being exploited in the wild.

Tracked as CVE-2026-48842, the flaw is a pre-authentication SQL injection in Roundcube’s built-in virtuser_query plugin, which handles database-driven user lookups and maps users to email addresses. In high-complexity attacks that require no user interaction, an attacker without privileges could bypass authentication, run malicious database commands and steal data from the Roundcube database.

Roundcube recommended upgrading to versions 1.6.16 or 1.7.1, which address the vulnerability. Shadowserver tracks more than 523,000 Roundcube instances exposed to the internet, but it has not reported how many are honeypots or have already been patched. Administrators unable to upgrade immediately can disable or remove the virtuser_query plugin to eliminate the attack vector.

Roundcube flaws have also been exploited by cybercrime and state-backed groups. Winter Vivern (TA473) used CVE-2023-5631 in attacks targeting European government entities. APT28 used CVE-2020-35730, CVE-2020-12641 and CVE-2021-44026 to breach Ukrainian government email systems. In February, the U.S. Cybersecurity and Infrastructure Security Agency flagged two other Roundcube flaws, CVE-2025-49113 and CVE-2025-68461, as actively exploited and gave government agencies three weeks to secure their networks. Since May 2022, the agency has listed 11 Roundcube Webmail vulnerabilities as exploited in the wild.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.