CVE-2026-48842Active Exploitation

CRITICALCVSS 8.1 · HIGH

Exploitation observed; activity peaked at 26 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.

8.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Active exploitation appears in 62 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 93 mentions across 14 observed days

What's happening

  • Active exploitation reported across 62 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 6 signals
  • Patch or workaround mentioned in 50 signals
  • Technical details provided in 71 signals
  • Disclosure: 10 classified signals
  • Peaked 6d ago at 26 mentions (2026-09-25); latest day: 2
  • 93 total mentions across 14 days

Deep dive

Activity timeline93 mentions / 14d
07132026Mentions · 2026-05-27: 1Mentions · 2026-05-28: 2Mentions · 2026-05-29: 2Mentions · 2026-06-02: 1Mentions · 2026-06-08: 4Mentions · 2026-06-28: 1Mentions · 2026-09-24: 18Mentions · 2026-09-25: 26Mentions · 2026-09-26: 12Mentions · 2026-09-27: 2Mentions · 2026-09-28: 15Mentions · 2026-09-29: 3Mentions · 2026-09-30: 4Mentions · 2026-10-01: 2PoC Mentioned / Linked · 2026-09-25: 1PoC Mentioned / Linked · 2026-09-28: 5Exploit Tool / Code · 2026-09-25: 1Exploit Tool / Code · 2026-09-28: 1Active Exploitation · 2026-09-24: 16Active Exploitation · 2026-09-25: 20Active Exploitation · 2026-09-26: 10Active Exploitation · 2026-09-27: 2Active Exploitation · 2026-09-28: 12Active Exploitation · 2026-09-29: 1Active Exploitation · 2026-10-01: 1Patch / Workaround · 2026-05-27: 1Patch / Workaround · 2026-05-28: 2Patch / Workaround · 2026-05-29: 1Patch / Workaround · 2026-06-08: 2Patch / Workaround · 2026-09-24: 12Patch / Workaround · 2026-09-25: 14Patch / Workaround · 2026-09-26: 8Patch / Workaround · 2026-09-28: 8Patch / Workaround · 2026-09-29: 1Patch / Workaround · 2026-10-01: 1Technical Details · 2026-05-27: 1Technical Details · 2026-05-28: 2Technical Details · 2026-05-29: 2Technical Details · 2026-06-08: 4Technical Details · 2026-09-24: 14Technical Details · 2026-09-25: 22Technical Details · 2026-09-26: 9Technical Details · 2026-09-27: 2Technical Details · 2026-09-28: 12Technical Details · 2026-09-29: 2Technical Details · 2026-10-01: 105-2705-2805-2906-0206-0806-2809-2409-2509-2609-2709-2809-2909-3010-01
Signal classification6 categories
Active Exploitation
6271.3%
Disclosure
1011.5%
Patch
89.2%
General
33.4%
PoC
33.4%
Exploit
11.1%
Referenced assets67 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-271
Patch1
2026-05-282
Patch2
2026-05-292
Disclosure2
2026-06-021
General1
2026-06-084
Disclosure1General1Patch2
2026-06-281
General1
2026-09-2418
Active Exploitation16Patch2
2026-09-2526
Active Exploitation20Disclosure5PoC1
2026-09-2612
Active Exploitation10Disclosure1Patch1
2026-09-272
Active Exploitation2
2026-09-2815
Active Exploitation12Exploit1PoC2
2026-09-293
Active Exploitation1Disclosure1
2026-10-012
Active Exploitation1
Full discourse20 posts
  • FOFA@fofabot
    Patch

    ⚠️⚠️ CVE-2026-48842 (CVSS 8.1) + CVE-2026-48844 (CVSS 7.5): Pre-auth SQLi in Roundcube virtuser_query plugin; patch to 1.6.16 / 1.7.1. 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJSb3VuZGN1YmUtV2VibWFpbCI= 🎯1.1M+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="Roundcube-Webmail" 🔖Refer: https://securityonline.info/roundcube-webmail-security-updates/ #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    The post announces two pre‑authentication SQL injection CVEs in Roundcube’s virtuser_query plugin, lists CVSS scores, and cites specific patch releases (1.6.16 / 1.7.1) for remediation.

    13611528215.3K
    14.4K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    🚨 Attackers are exploiting a Roundcube pre-auth SQL injection flaw patched in May. CVE-2026-48842 can expose mail credentials and stored messages through the virtuser_query plugin. Read: https://thehackernews.com/2026/09/roundcube-pre-auth-sql-injection-flaw.html

    Post summary

    The text reports active exploitation of CVE-2026-48842, a pre-auth SQL injection flaw in Roundcube, which was patched in May and could expose mail credentials and stored messages via the virtuser_query plugin.

    7221973038.8K
    2.4M followersView on X
  • Hunter@HunterMapping
    Disclosure

    🚨Alert🚨 CVE-2026-48842 (CVSS 8.1) && CVE-2026-48842-CVE-2026-48849 :Critical Roundcube Webmail Security Updates Fix Severe Flaws 📊 2.6M+ Services are found on the http://hunter.how yearly. 🔗Hunter Link:https://hunter.how/list?searchValue=product.name%3D%22Roundcube%20Webmail%22 👇Query HUNTER : http://product.name="Roundcube Webmail" 📰Refer:https://securityonline.info/roundcube-webmail-security-updates/ #hunterhow #infosec #infosecurity #OSINT #Vulnerability

    Post summary

    An alert announces new Roundcube Webmail CVEs with high CVSS scores, but offers no evidence of PoC, exploit tools, or detailed patch guidance.

    018183386.8K
    26.0K followersView on X
  • Dark Web Informer@DarkWebInformer
    Active Exploitation

    🚨 Roundcube SQL injection flaw actively exploited months after patches were released The Canadian Centre for Cyber Security has warned that CVE-2026-48842, a high-severity vulnerability in Roundcube Webmail, is being exploited in the wild. ⠀ Roundcube is an open-source webmail application that lets people access email through a browser. The flaw affects its virtuser_query plugin and allows SQL injection before authentication. ⠀ Key details: • CVSS score: 8.1 • No attacker credentials required • No user interaction required • Affects Roundcube 1.6.x before 1.6.16 and 1.7.x before 1.7.1 ⠀ Roundcube released the original fixes on May 24, 2026. Canada added the exploitation warning to its advisory on September 21, citing open-source reporting. The advisory does not identify the attackers, victims or scale of exploitation. ⠀ Administrators should update affected installations promptly. Newer security releases, 1.6.19 and 1.7.4, also address additional vulnerabilities.

    Post summary

    The text confirms active exploitation of CVE-2026-48842 in the wild for Roundcube Webmail, citing the Canadian Centre for Cyber Security, and urges immediate updates to patched versions.

    181511410.7K
    242.7K followersView on X
  • ThreatWire@ThreatWire_
    Active Exploitation

    🚨 EXPLOITED IN THE WILD: CVE-2026-48842 — High-severity pre-authentication SQL injection in Roundcube Webmail (CVSS 8.1). The flaw affects the virtuser_query plugin and can allow unauthenticated attackers to manipulate database queries through a backslash escaping bypass. ⚠️ Affects Roundcube 1.6.x before 1.6.16 and 1.7.x before 1.7.1. 🔴 Update to Roundcube 1.6.16 or 1.7.1. PoC: https://github.com/4minx/cve-2026-48842 Source: https://www.cyber.gc.ca/en/alerts-advisories/roundcube-security-advisory-av26-503 #CVE #CyberSecurity #Roundcube #SQLInjection #Infosec

    Post summary

    CVE-2026-48842 is confirmed as actively exploited in the wild, with a PoC linked, technical details including pre-authentication SQL injection (CVSS 8.1) provided, and a patch/update to Roundcube 1.6.16/1.7.1 recommended.

    06030183.6K
    1.8K followersView on X
  • Aircorridor@_aircorridor

    Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild Severity: HIGH When exploited, this vulnerability allows an attacker to manipulate SQL queries in a way that can compromise the database without needing to authenticate. https://github.com/4minx/CVE-2026-48842

    0802571.4K
    14.8K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    PoC

    🔴 CVE-2026-48842 - Roundcube Webmail'de virtuser_query yapılandırması etkinse, kimlik doğrulama gerektirmeyen SQL Injection açığı için @murrezsec tarafından PoC yayınlandı. 🔴 CVSS 8.1 — High 🔓 Pre-auth / PR:N 🧩 virtuser_quer plugin 🐍 Python PoC: sürüm + plugin tespiti ve aktif SQLi probe Etkilenen sürümler: 1.6.x < 1.6.16, 1.7.x < 1.7.1 Yamalanan sürümler: 1.6.16 / 1.7.1 ve üzeri PoC: https://github.com/murrez/CVE-2026-48842

    Post summary

    The tweet discloses CVE-2026-48842, a pre-authentication SQL Injection in Roundcube Webmail, linking a Python PoC on GitHub and listing affected and fixed versions, with no indication of active exploitation in the wild.

    00013111.3K
    2.4K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    PoC

    🔴 CVE-2026-48842, Roundcube Webmail'deki virtuser_query eklentisinde kimlik doğrulama gerektirmeyen (pre-auth) SQL Injection açığı için yeni bir PoC yayınlandı. Roundcube yazılımınızı halen güncellemediyseniz, 1.6.16, 1.7.1 veya daha yeni sürüme güncelleyin. https://github.com/4minx/cve-2026-48842

    Post summary

    The tweet announces a PoC for CVE-2026-48842, a pre‑auth SQL injection in Roundcube's virtuser_query plugin, and urges users to update to version 1.6.16, 1.7.1, or later.

    030114708
    2.4K followersView on X
  • ExploitGrid@exploitgrid
    Active Exploitation

    🚨 CVE-2026-48842 is reportedly being exploited in the wild. Roundcube Webmail has a pre-auth SQL injection in the virtuser_query plugin, affecting versions before 1.6.16 and 1.7.1. CVSS 8.1 | Public exploit ExploitGrid: 40.7/100 Medium 🔎 https://exploitgrid.net/vulnerabilities/CVE-2026-48842

    Post summary

    The alert reports active exploitation of CVE-2026-48842, a pre-auth SQL injection in Roundcube Webmail (virtuser_query plugin), noting a public exploit exists and fixed versions are 1.6.16 and 1.7.1.

    01063421
    378 followersView on X
  • Pierluigi Paganini - Security Affairs@securityaffairs
    Active Exploitation

    #Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild https://securityaffairs.com/199882/security/roundcube-sql-injection-cve-2026-48842-is-now-being-exploited-in-the-wild.html #securityaffairs #hacking

    Post summary

    The tweet reports that CVE-2026-48842, a Roundcube SQL injection flaw, is currently being exploited in the wild.

    04042859
    37.7K followersView on X
  • ExploitGrid@exploitgrid
    PoC

    🚨 PoC for CVE-2026-48842 is now public. Roundcube Webmail has a pre-auth SQL injection affecting versions before 1.6.16 and 1.7.1. CVSS 8.1 | Public exploit | EG 40.7 🔎 https://exploitgrid.net/vulnerabilities/CVE-2026-48842

    Post summary

    The tweet announces that a Proof of Concept for CVE-2026-48842, a pre-auth SQL injection in Roundcube Webmail, is now public, including a CVSS score and a link to further details.

    02061239
    378 followersView on X
  • Rıdvan Yağlı@ridvanyagli
    Active Exploitation

    🔴 Roundcube'daki pre-auth SQL Injection açığı (CVE-2026-48842 - CVSS 8.1), saldırılarda aktif olarak kullanılmaya başlandı. Açık virtuser_query eklentisini etkiliyor ve kimlik doğrulama gerektirmiyor. Halen yapmadıysanız son sürüme güncellemeyi unutmayın.

    Post summary

    The tweet reports a pre‑auth SQL injection in Roundcube (CVE‑2026‑48842, CVSS 8.1) that is already being actively exploited in the wild, and urges users to update to the latest version to mitigate it.

    011611.9K
    2.4K followersView on X
  • FastFoodRembrandt.onion@solminingpunk
    Active Exploitation

    🚨‼️ALERT @roundcube SQL injection CVE-2026-48842 is now being exploited in the wild A Roundcube Webmail vulnerability, tracked as CVE-2026-48842 (CVSS score of 8.1) and patched four months ago, is now being exploited in the wild. #cybersecurity https://ift.tt/domk749

    Post summary

    The tweet alerts that CVE-2026-48842, a SQL injection vulnerability in Roundcube Webmail with a CVSS 8.1 score, is actively being exploited in the wild despite a patch being available for four months.

    10060360
    6.8K followersView on X
  • N A I F@naif_aiydh
    Active Exploitation

    ثغرة في Roundcube Webmail تُستغل فعليًا بعد أربعة أشهر من إصلاحها ⚠️ CVE-2026-48842: حقن SQL دون مصادقة، وتشمل الإصدارات قبل 1.6.16 و1.7.1. حذّر منها المركز الكندي للأمن السيبراني، ويرصد Shadowserver أكثر من 523 ألف خادم Roundcube مكشوف على الإنترنت. https://www.bleepingcomputer.com/news/security/critical-roundcube-flaw-now-actively-exploited-in-code-injection-attacks/

    Post summary

    CVE-2026-48842 is an unauthenticated SQL injection in Roundcube Webmail that is being actively exploited in the wild, with over 523,000 internet-exposed servers identified.

    00032592
    7.2K followersView on X
  • 0x870x4k3r@pepetheshneine
    Active Exploitation

    2/6 Roundcube — CVE-2026-48842 Pre-auth SQLi in virtuser_query is being exploited in the wild. Affected: • 1.6.x &lt; 1.6.16 • 1.7.x &lt; 1.7.1 Common in hosting stacks and cPanel. If your webmail is public, patch it now. https://www.cyber.gc.ca/en/alerts-advisories/roundcube-security-advisory-av26-503

    Post summary

    The post warns that CVE-2026-48842, a pre-authentication SQL injection in Roundcube, is actively exploited in the wild and urges immediate patching to versions 1.6.16 or 1.7.1.

    2001058
    29 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Active Exploitation

    Critical Roundcube flaw CVE-2026-48842 is being actively exploited in the wild, enabling pre-auth SQL injection via virtuser_query and possible auth bypass. #Roundcube #Canada #CVE-2026-48842 https://www.hendryadrian.com/hackers-now-exploit-critical-roundcube-flaw-in-code-injection-attacks/

    Post summary

    The tweet reports that CVE-2026-48842 in Roundcube is actively exploited in the wild via pre-auth SQL injection (virtuser_query) and possible auth bypass, with no patch or workaround mentioned.

    11010300
    4.9K followersView on X
  • YourDailyCVE@YourDailyCVE

    🚨 CVE-2026-48842 — Roundcube Webmail, unauthenticated SQL injection. CVSS 8.1. No KEV yet. Patched 4 months ago. What broke: virtuser_query looks up mailbox usernames by email address and tries to escape input with a regex before building the SQL query. The escaping has a bypass. No login required — an attacker injects SQL straight into the pre-auth lookup. Who should care: anyone running Roundcube 1.6.x below 1.6.16 or 1.7.x below 1.7.1, especially with the virtuser_query plugin enabled. Over 500,000 Roundcube instances are exposed to the internet right now. Status: Roundcube fixed this quietly in May. Four months of silence, then on Sep 21 Canada's cyber center updated its advisory to say open-source reporting shows real exploitation. Not on CISA's KEV catalog as of this week, so no federal deadline forcing the issue — just a national CERT saying attackers are using it. Roundcube's had a rough year: a different set of bugs got used by a China-linked group in July to drop web shells. Fix today: update to 1.6.16 / 1.7.1 or later — 1.6.19 and 1.7.4 are current if you want more than just patched. Can't patch: virtuser_query is an optional plugin, not core. Disabling it removes the vulnerable code path entirely — a real stopgap, not just delay. Do this now: if you run Roundcube, check your version and reply "patched." Source: Roundcube 1.6.16/1.7.1 release notes / Canadian Centre for Cyber Security AV26-503 / Shadowserver #Roundcube #Webmail

    0002088
    34 followersView on X
  • Threat Landscape@LandscapeThreat

    Roundcube webmail servers are now an exploitation target. CVE-2026-48842 is a pre-authentication SQL injection in the virtuser_query plugin. Specially crafted backslash sequences can bypass escaping and inject SQL without authentication. The Canadian Centre for Cyber Security reported active exploitation based on open-source reporting. Roundcube 1.6.x before 1.6.16 and 1.7.x before 1.7.1 are affected. Fixes shipped May 24, 2026. Successful exploitation could expose database contents, including mailbox credentials and stored messages, depending on database permissions and configuration. The report lists actor UNK_MassTraction and malware VShell, but provides no reliable IOCs or attribution. Its vulnerability set also includes CVE-2025-68461 and CVE-2025-49113. Treat this as OSINT: verify exposure and patch affected systems. Get the dossier on our platform, ATT&CK-mapped, sourced and exportable.

    0002048
    96 followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Active Exploitation

    Learn how hackers are exploiting the CVE-2026-48842 Roundcube SQL injection vulnerability. Understand the risk and how to patch your webmail server immediately. #Roundcube #CyberSecurity #SQLInjection #DataBreach #TechNews https://meterpreter.org/roundcube-webmail-sql-injection/

    Post summary

    The post announces that CVE-2026-48842 in Roundcube involves SQL injection and claims hackers are actively exploiting it, while urging immediate patching.

    00020445
    13.0K followersView on X
  • Abijita Foundation@OfficialAbijita
    Active Exploitation

    Roundcube Webmail Vulnerability CVE-2026-48842 Actively Exploited https://www.abijita.com/roundcube-webmail-vulnerability-cve-2026-48842-actively-exploited/

    Post summary

    The text highlights that the Roundcube Webmail vulnerability, CVE-2026-48842, is actively being exploited, directing readers to an external article for further information.

    01010103
    516 followersView on X

Explore more