LmCast :: Stay tuned in

Hackers now exploit critical Roundcube flaw in code injection attacks

Recorded: Sept. 24, 2026, 2 p.m.

Original Summarized

Hackers now exploit critical Roundcube flaw in code injection attacks

News

Featured
Latest

ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach

New Windows Defender zero-day blocks Microsoft antivirus updates

EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts

Check Point warns of Management Server zero-day exploited in attacks

Hackers now exploit critical Roundcube flaw in code injection attacks

Windows 11 KB5124010 update released with 46 changes and fixes

Get AI-powered Autodesk AutoCAD for $399, save $1,696

CISA: Ransomware gangs now exploiting critical TeamCity flaw

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecurityHackers now exploit critical Roundcube flaw in code injection attacks

Hackers now exploit critical Roundcube flaw in code injection attacks

By Sergiu Gatlan

September 24, 2026
09:27 AM
0

A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security.
Roundcube Webmail is a browser-based IMAP email client used as the default mail interface by thousands of services with millions of users, and it is pre-installed with the widely used cPanel web hosting control panel.
In May, the Roundcube security team patched the flaw (tracked as CVE-2026-48842), describing it as a pre-authenticated SQL injection in the virtuser_query built-in plugin, which handles database-driven user lookups and maps users to email addresses.
Successful exploitation can let threat actors with no privileges bypass authentication, inject and execute malicious database commands, and steal data from Roundcube's database in high-complexity attacks that don't require user interaction.
Roundcube also "strongly" recommended that users update their servers to versions 1.6.16 and 1.7.1, which address this vulnerability.
Threat monitoring non-profit Shadowserver now tracks over 523,000 Roundcube instances exposed on the Internet. However, there is no information on how many are honeypots or have already been patched against this flaw.

Roundcube instances exposed online (Shadowserver)
Flagged as actively exploited
On Monday, four months after CVE-2026-48842 was patched, the Canadian Centre for Cyber Security updated its May advisory to warn that attackers are now actively exploiting it.
"Open-source reporting indicates that CVE-2026-48842 is being exploited in the wild," the Cyber Center warned, urging administrators to secure their webmail servers.
While a security update is available to block ongoing attacks, admins who can't immediately upgrade their servers should disable or remove the virtuser_query plugin to eliminate the attack vector.
Roundcube security flaws have been a popular target for both cybercrime and state-backed hacking groups, with the Winter Vivern (TA473) Russian threat group exploiting a cross-site scripting (XSS) zero-day (CVE-2023-5631) in attacks targeting European government entities and the Russian APT28 cyber-espionage group abusing multiple flaws (CVE-2020-35730, CVE-2020-12641, and CVE-2021-44026) to breach Ukrainian government email systems.
More recently, in February, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) flagged two other Roundcube flaws (CVE-2025-49113 and CVE-2025-68461) as actively exploited and ordered government agencies to secure their networks within three weeks.
Since May 2022, the cybersecurity agency has tagged 11 Roundcube Webmail vulnerabilities as exploited in the wild.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Save your seat

Related Articles:
Check Point warns of hackers exploiting Security Gateway VPN RCE flawHackers start exploiting critical WordPress flaw for code executionInfraTrust report warns network management systems under attackArista patches actively exploited VeloCloud Orchestrator zero-dayF5 patches BIG-IP APM zero-day flaw exploited in RCE attacks

Actively Exploited
Canada
Code Injection
CVE-2026-48842
Email
Mail
Roundcube
Vulnerability

Sergiu Gatlan
Sergiu is a news reporter who has covered the latest cybersecurity and technology developments for over a decade. Email or Twitter DMs for tips.

Previous Article
Next Article

Post a Comment Community Rules

You need to login in order to post a comment

Not a member yet? Register Now

You may also like:

  Upcoming Webinar

Popular Stories

ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach

Microsoft reminds admins to migrate Entra ID users to passkeys

New Windows Defender zero-day blocks Microsoft antivirus updates

Sponsor Posts

AI is a data-breach time bomb: Read the new report

Build cyber resilience with Wazuh: The open-source SIEM & XDR for proactive protection

Overdue a password health-check? Audit your Active Directory for free

Automate Onboarding and Access Reviews with No-Code IGA: See how it works

Daily detection, monthly validation, 12-hour clocks. Are you VDR & VER ready?

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

Hackers are currently exploiting a critical flaw in Roundcube Webmail through code injection attacks, according to the Canadian Centre for Cyber Security. This vulnerability, tracked as CVE-2026-48842, stems from a pre-authenticated SQL injection within the virtuser_query built-in plugin, which is responsible for handling database-driven user lookups and mapping users to email addresses. Successful exploitation permits threat actors lacking elevated privileges to bypass standard authentication procedures, inject and execute malicious database commands, and subsequently steal data from the Roundcube database, often achievable through high-complexity attacks that do not require direct user interaction. Roundcube itself advised users to update their server versions to 1.6.16 and 1.7.1 to remediate this issue.

Threat monitoring non-profit Shadowserver tracks over 523,000 Roundcube instances exposed on the Internet, though there is no available data on how many of these are honeypots or have been secured against this specific vulnerability. The Canadian Centre for Cyber Security updated its advisory to warn that exploitation of CVE-2026-48842 is actively occurring in the wild, prompting administrators to secure their webmail servers immediately. For those who cannot perform an immediate server upgrade, the advisory suggests disabling or removing the virtuser_query plugin to eliminate the potential attack vector.

Roundcube security flaws have historically been attractive targets for both cybercrime and state-backed hacking groups. For example, the Winter Vivern Russian threat group utilized a cross-site scripting zero-day vulnerability (CVE-2023-5631) in attacks against European government entities, while the Russian APT28 cyber-espionage group leveraged multiple flaws, including CVE-2020-35730, CVE-2020-12641, and CVE-2021-44026, to breach Ukrainian government email systems. More recently, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) also flagged two other Roundcube flaws, CVE-2025-49113 and CVE-2025-68461, as actively exploited, issuing a directive for government agencies to secure their networks within three weeks. Since May 2022, the cybersecurity agency has tagged eleven Roundcube Webmail vulnerabilities as actively exploited in the wild, underscoring the persistent risk associated with these systems.