The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild.
The flaw, identified as CVE-2026-48842 and rated 8.1 on the CVSS scale, is a pre‑authentication SQL injection that affects the virtuser_query plugin in Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1. The issue arises from a backslash in a preg_replace() call that allows attackers to inject malicious SQL code before a user logs in.
According to the Canadian Centre for Cyber Security, the vulnerability is already being exploited by threat actors in the wild, despite the fact that the vendor has released a patch to address the issue.
Users of affected Roundcube installations are urged to apply the latest security update immediately to prevent potential data breaches or unauthorized database access.
Roundcube is a widely used open‑source webmail client that powers many small and medium‑sized organisations, making timely updates critical to maintaining secure email services.
<small>Source: The Hacker News — read the original story there.</small>