Hackers now exploit critical Roundcube flaw in code injection attacks
Recorded: Sept. 24, 2026, 2 p.m.
| Original | Summarized |
Hackers now exploit critical Roundcube flaw in code injection attacks News Featured ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach New Windows Defender zero-day blocks Microsoft antivirus updates EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts Check Point warns of Management Server zero-day exploited in attacks Hackers now exploit critical Roundcube flaw in code injection attacks Windows 11 KB5124010 update released with 46 changes and fixes Get AI-powered Autodesk AutoCAD for $399, save $1,696 CISA: Ransomware gangs now exploiting critical TeamCity flaw Tutorials Latest How to access the Dark Web using the Tor Browser How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 How to use the Windows Registry Editor How to backup and restore the Windows Registry How to start Windows in Safe Mode How to remove a Trojan, Virus, Worm, or other Malware How to show hidden files in Windows 7 How to see hidden files in Windows Webinars Latest Qualys BrowserCheck STOPDecrypter AuroraDecrypter FilesLockerDecrypter AdwCleaner ComboFix RKill Junkware Removal Tool Deals Categories eLearning IT Certification Courses Gear + Gadgets Security VPNs Popular Best VPNs How to change IP address Access the dark web safely Best VPN for YouTube Forums Virus Removal Guides HomeNewsSecurityHackers now exploit critical Roundcube flaw in code injection attacks Hackers now exploit critical Roundcube flaw in code injection attacks By Sergiu Gatlan September 24, 2026 A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security. Roundcube instances exposed online (Shadowserver) Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Related Articles: Actively Exploited Sergiu Gatlan Previous Article Post a Comment Community Rules You need to login in order to post a comment Not a member yet? Register Now You may also like: Upcoming Webinar Popular Stories ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach Microsoft reminds admins to migrate Entra ID users to passkeys New Windows Defender zero-day blocks Microsoft antivirus updates Sponsor Posts AI is a data-breach time bomb: Read the new report Build cyber resilience with Wazuh: The open-source SIEM & XDR for proactive protection Overdue a password health-check? Audit your Active Directory for free Automate Onboarding and Access Reviews with No-Code IGA: See how it works Daily detection, monthly validation, 12-hour clocks. Are you VDR & VER ready? Follow us: Main Sections News Community Forums Useful Resources Welcome Guide Company About BleepingComputer Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved Login Username Password Remember Me Sign in anonymously Sign in with Twitter Not a member yet? Register Now Help us understand the problem. What is going on with this comment? Spam Abusive or Harmful Inappropriate content Strong language Other Read our posting guidelinese to learn what content is prohibited. Submitting... |
Hackers are currently exploiting a critical flaw in Roundcube Webmail through code injection attacks, according to the Canadian Centre for Cyber Security. This vulnerability, tracked as CVE-2026-48842, stems from a pre-authenticated SQL injection within the virtuser_query built-in plugin, which is responsible for handling database-driven user lookups and mapping users to email addresses. Successful exploitation permits threat actors lacking elevated privileges to bypass standard authentication procedures, inject and execute malicious database commands, and subsequently steal data from the Roundcube database, often achievable through high-complexity attacks that do not require direct user interaction. Roundcube itself advised users to update their server versions to 1.6.16 and 1.7.1 to remediate this issue. Threat monitoring non-profit Shadowserver tracks over 523,000 Roundcube instances exposed on the Internet, though there is no available data on how many of these are honeypots or have been secured against this specific vulnerability. The Canadian Centre for Cyber Security updated its advisory to warn that exploitation of CVE-2026-48842 is actively occurring in the wild, prompting administrators to secure their webmail servers immediately. For those who cannot perform an immediate server upgrade, the advisory suggests disabling or removing the virtuser_query plugin to eliminate the potential attack vector. Roundcube security flaws have historically been attractive targets for both cybercrime and state-backed hacking groups. For example, the Winter Vivern Russian threat group utilized a cross-site scripting zero-day vulnerability (CVE-2023-5631) in attacks against European government entities, while the Russian APT28 cyber-espionage group leveraged multiple flaws, including CVE-2020-35730, CVE-2020-12641, and CVE-2021-44026, to breach Ukrainian government email systems. More recently, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) also flagged two other Roundcube flaws, CVE-2025-49113 and CVE-2025-68461, as actively exploited, issuing a directive for government agencies to secure their networks within three weeks. Since May 2022, the cybersecurity agency has tagged eleven Roundcube Webmail vulnerabilities as actively exploited in the wild, underscoring the persistent risk associated with these systems. |