Active Exploitation of Vulnerability in Roundcube Webmail
3 October 2026
Attackers are exploiting a high-severity vulnerability in Roundcube Webmail to perform SQL injection without authentication. Patch immediately.
Background
Roundcube has released security updates to address a high-severity vulnerability (CVE-2026-48842) affecting Roundcube Webmail. This vulnerability has a Common Vulnerability Scoring System (CVSS v3.1) score of 8.1 out of 10.
Impact
Successful exploitation of this pre-authentication SQL injection vulnerability in the virtuser_query plugin could allow an unauthenticated attacker to inject arbitrary SQL statements into the underlying database.
Known Exploitation
This vulnerability is reportedly being actively exploited.
Affected Products
The vulnerability affects the following products:
Roundcube Webmail versions 1.6.0 to before 1.6.16
Roundcube Webmail versions 1.7.0 to before 1.7.1
Users and administrators should refer to the vendor advisory below for the full list of affected versions.
Recommendations
Users and administrators of affected products are advised to update to the latest versions immediately.
References
