INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Roundcube SQL Injection CVE-2026-48842 Exploited in the Wild
| 2026-09-28 05:50 CRITICAL HIGHExecutive Summary AI-generated
The Roundcube vulnerability, CVE-2026-48842, has been exploited in the wild due to a critical contextual issue. This flaw affects versions of Roundcube before 1.6.16 and 1.7.1, but its presence is not isolated from other vulnerabilities. The Canadian Centre for Cyber Security's advisory warns that an unauthenticated attacker can inject SQL into Roundcube's database backend through the virtuser_query plugin, potentially exposing mail account credentials and stored messages. This highlights a significant risk to email applications with vulnerable databases. Multiple attacks have targeted multiple Roundcube flaws in the past, emphasizing the need for timely patches from the software developers.
Technical Mitigations AI-generated
* Implement input validation and sanitization for user-submitted data, particularly for email addresses and usernames, to prevent pre-authentication SQL injection attacks.
* Regularly update and patch vulnerable software, including Roundcube Webmail, to ensure that known exploits are addressed before they can be used against the system.
* Monitor web application logs and security alerts to detect potential exploitation attempts in real-time, allowing for swift action to be taken if necessary.
* Educate users about the risks of SQL injection attacks and provide guidance on how to protect themselves, such as avoiding suspicious input or using prepared statements when interacting with databases.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
APT28APT28Winter VivernWinter Vivern
CVE-2020-12641CVE-2020-12641
CVE-2021-44026CVE-2021-44026
CVE-2025-49113CVE-2025-49113
CVE-2026-48842CVE-2026-48842
CVE-2023-5631CVE-2023-5631
CVE-2020-35730CVE-2020-35730
CVE-2025-68461CVE-2025-68461
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
governmentgovernment
Incident Timeline
May 2022
Threat actors exploited a Roundcube Pre-Auth SQL Injection flaw in the wild since May 2022.
Click on any entity below to view its context and source!
infrastructure
Roundcube
Since May 2022, the cybersecurity agency
has tagged 11 Roundcube Webmail vulnerabilities
as exploited in the wild.
general_metric
11 Roundcube Webmail
Since May 2022, the cybersecurity agency
has tagged 11 Roundcube Webmail vulnerabilities
as exploited in the wild.
February 2026
Threat actors exploited a Roundcube Pre-Auth SQL Injection flaw in the wild.
Click on any entity below to view its context and source!
vulnerability
CVE-2025-49113
Way back in February 2026, two other vulnerabilities in the same product (CVE-2025-49113 and CVE-2025-68461) were
tagged
as actively exploited by the U.S. Cybersecurity and Infrastructure Security Agency (CISA).
attribution
CVE-2025-68461
Way back in February 2026, two other vulnerabilities in the same product (CVE-2025-49113 and CVE-2025-68461) were
tagged
as actively exploited by the U.S. Cybersecurity and Infrastructure Security Agency (CISA).
May 24, 2026
Roundcube released the fixes on May 24, 2026.
Click on any entity below to view its context and source!
infrastructure
Roundcube
Roundcube released the fixes on May 24, 2026.
May 2026
Threat actors exploited a Roundcube pre-auth SQL injection flaw in the wild using Patches for the vulnerability released by Roundcube in May 2026 as part of version 1.6.16 and 1.7.1.
Click on any entity below to view its context and source!
infrastructure
Roundcube
Patches for the vulnerability were
released
by Roundcube in May 2026 as part of 1.6.16 and 1.7.1.
infrastructure
1.6.16
Patches for the vulnerability were
released
by Roundcube in May 2026 as part of 1.6.16 and 1.7.1.
infrastructure
1.7.1
Patches for the vulnerability were
released
by Roundcube in May 2026 as part of 1.6.16 and 1.7.1.
July 2026
Threat actors used a known security flaw in Roundcube to exploit and deliver web shells or a post-exploitation tool called VShell.
Click on any entity below to view its context and source!
source_region
China
In July 2026, Proofpoint said it identified a suspected China-aligned adversary dubbed
UNK_MassTraction
exploiting known security flaws in Roundcube to deliver web shells or a post-exploitation tool called VShell.
infrastructure
Roundcube
In July 2026, Proofpoint said it identified a suspected China-aligned adversary dubbed
UNK_MassTraction
exploiting known security flaws in Roundcube to deliver web shells or a post-exploitation tool called VShell.
organisation
VShell
In July 2026, Proofpoint said it identified a suspected China-aligned adversary dubbed
UNK_MassTraction
exploiting known security flaws in Roundcube to deliver web shells or a post-exploitation tool called VShell.
September 21
The Canadian Centre for Cyber Security issued a warning on September 21 about the Roundcube pre-auth SQL injection flaw in its software.
Click on any entity below to view its context and source!
organisation
The Canadian Centre for Cyber Security
The Canadian Centre for Cyber Security added the warning to its advisory on September 21, citing open-source reporting and urging administrators to apply the available updates.
September 23, 2026
Threat actors exploited a pre-auth SQL injection flaw in Roundcube, compromising more than 523,000 exposed instances.
Click on any entity below to view its context and source!
infrastructure
Roundcube
Data from the Shadowserver Foundation shows that there are
more than 523,000 Roundcube instances
exposed to the internet, with 10 of them
flagged
as vulnerable hosts as of September 23, 2026.
organisation
the Shadowserver Foundation
Data from the Shadowserver Foundation shows that there are
more than 523,000 Roundcube instances
exposed to the internet, with 10 of them
flagged
as vulnerable hosts as of September 23, 2026.
general_metric
523,000 Roundcube instances
Data from the Shadowserver Foundation shows that there are
more than 523,000 Roundcube instances
exposed to the internet, with 10 of them
flagged
as vulnerable hosts as of September 23, 2026.
general_metric
10 internet
Data from the Shadowserver Foundation shows that there are
more than 523,000 Roundcube instances
exposed to the internet, with 10 of them
flagged
as vulnerable hosts as of September 23, 2026.
Sep 25, 2026
Threat actors exploited a pre-authentication SQL injection flaw in Roundcube, a popular open-source web server software.
September 28, 2026
Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild, putting unpatched webmail servers at risk of database compromise.
Click on any entity below to view its context and source!
infrastructure
Roundcube
Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild
Pierluigi Paganini
September 28, 2026
Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild, putting unpatched webmail servers at risk of database compromise.
vulnerability
CVE-2026-48842
Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild
Pierluigi Paganini
September 28, 2026
Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild, putting unpatched webmail servers at risk of database compromise.
2026/09/28
Roundcube vulnerabilities are being actively exploited in the wild.
Click on any entity below to view its context and source!
infrastructure
Roundcube
In July, Proofpoint
reported
activity by a suspected China-nexus actor tracked as UNK_MassTraction, which exploited known Roundcube vulnerabilities to deploy web shells or VShell, a post-exploitation tool.
Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild.
A Roundcube Webmail vulnerability, tracked as CVE-2026-48842 (CVSS score of 8.1) and patched four months ago, is now being exploited in the wild.
The vulnerability CVE-2026-48842 affects Roundcube 1.6.x versions before 1.6.16 and 1.7.x versions before 1.7.1, but there’s an important detail: the vulnerable code sits in the
virtuser_query
plugin.
That gives an unauthenticated attacker a direct path to the database behind Roundcube.
This means an attacker does not need to authenticate to access the database behind Roundcube.
“Unauthenticated attackers can inject SQL into Roundcube’s database backend through the virtuser_query plugin, potentially exposing mail account credentials and stored messages.”
warns SentinelOne
.
Roundcube is an email application, and its database can contain information that becomes extremely useful once an attacker gets access to it.
Roundcube fixed the problem in May, but the exploitation warning arrived in September.
Threat actors have targeted multiple Roundcube flaws in attacks in the past.
In February, CISA listed
CVE-2025-49113
and
CVE-2025-68461
as actively exploited Roundcube vulnerabilities.
Roundcube has repeatedly appeared in attacks where a public-facing mail interface provides an initial point of access.
For defenders, the first step is to check which Roundcube versions are running.
However, this should not replace updating Roundcube.
Organizations with exposed Roundcube servers should therefore review application logs for signs of exploitation.
Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild.
Ravie Lakshmanan
Sep 25, 2026
Vulnerability / Email Security
The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild.
The vulnerability in question is
CVE-2026-48842
(CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.
"Unauthenticated attackers can inject SQL into Roundcube's database backend through the virtuser_query plugin, potentially exposing mail account credentials and stored messages," SentinelOne
said
.
Vulnerabilities in Roundcube have been an attractive target for threat actors looking to harvest sensitive email communications.
Roundcube security flaws have been a popular target for both cybercrime and state-backed hacking groups, with the Winter Vivern (TA473) Russian threat group exploiting a cross-site scripting (XSS) zero-day (CVE-2023-5631) in
attacks targeting European government entities
and the Russian APT28 cyber-espionage group abusing multiple flaws (CVE-2020-35730, CVE-2020-12641, and CVE-2021-44026)
to breach Ukrainian government email systems
.
More recently, in February, the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
flagged two other Roundcube flaws
(CVE-2025-49113 and CVE-2025-68461) as actively exploited and ordered government agencies to secure their networks within three weeks.
Hackers now exploit critical Roundcube flaw in code injection attacks.
A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security.
Roundcube Webmail is a browser-based IMAP email client used as the default mail interface by thousands of services with millions of users, and it is pre-installed with the widely used cPanel web hosting control panel.
In May, the Roundcube security team
patched the flaw
(tracked as
CVE-2026-48842
), describing it as a pre-authenticated SQL injection in the virtuser_query built-in plugin, which handles database-driven user lookups and maps users to email addresses.
Successful exploitation can let threat actors with no privileges bypass authentication, inject and execute malicious database commands, and steal data from Roundcube's database in high-complexity attacks that don't require user interaction.
Roundcube also "strongly" recommended that users update their servers to versions 1.6.16 and 1.7.1, which address this vulnerability.
Threat monitoring non-profit Shadowserver
now tracks over 523,000 Roundcube instances
exposed on the Internet.
Roundcube instances exposed online
organisation
VShell
In July, Proofpoint
reported
activity by a suspected China-nexus actor tracked as UNK_MassTraction, which exploited known Roundcube vulnerabilities to deploy web shells or VShell, a post-exploitation tool.
infrastructure
1.6
The vulnerability CVE-2026-48842 affects Roundcube 1.6.x versions before 1.6.16 and 1.7.x versions before 1.7.1, but there’s an important detail: the vulnerable code sits in the
virtuser_query
plugin.
The vulnerability in question is
CVE-2026-48842
(CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.
infrastructure
1.6.16
The vulnerability CVE-2026-48842 affects Roundcube 1.6.x versions before 1.6.16 and 1.7.x versions before 1.7.1, but there’s an important detail: the vulnerable code sits in the
virtuser_query
plugin.
The vulnerability in question is
CVE-2026-48842
(CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.
Roundcube also "strongly" recommended that users update their servers to versions 1.6.16 and 1.7.1, which address this vulnerability.
Versions older than 1.6.16 or 1.7.1 should be considered vulnerable.
infrastructure
1.7
The vulnerability CVE-2026-48842 affects Roundcube 1.6.x versions before 1.6.16 and 1.7.x versions before 1.7.1, but there’s an important detail: the vulnerable code sits in the
virtuser_query
plugin.
The vulnerability in question is
CVE-2026-48842
(CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.
infrastructure
1.7.1
The vulnerability CVE-2026-48842 affects Roundcube 1.6.x versions before 1.6.16 and 1.7.x versions before 1.7.1, but there’s an important detail: the vulnerable code sits in the
virtuser_query
plugin.
The vulnerability in question is
CVE-2026-48842
(CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.
Roundcube also "strongly" recommended that users update their servers to versions 1.6.16 and 1.7.1, which address this vulnerability.
Versions older than 1.6.16 or 1.7.1 should be considered vulnerable.
organisation
SentinelOne
“Unauthenticated attackers can inject SQL into Roundcube’s database backend through the virtuser_query plugin, potentially exposing mail account credentials and stored messages.”
warns SentinelOne
.
"Unauthenticated attackers can inject SQL into Roundcube's database backend through the virtuser_query plugin, potentially exposing mail account credentials and stored messages," SentinelOne
said
.
organisation
The Canadian Centre for Cyber Security
Ravie Lakshmanan
Sep 25, 2026
Vulnerability / Email Security
The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild.
A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security.
organisation
Vulnerability / Email Security
Ravie Lakshmanan
Sep 25, 2026
Vulnerability / Email Security
The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild.
organisation
SQL
The vulnerability in question is
CVE-2026-48842
(CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.
In May, the Roundcube security team
patched the flaw
(tracked as
CVE-2026-48842
), describing it as a pre-authenticated SQL injection in the virtuser_query built-in plugin, which handles database-driven user lookups and maps users to email addresses.
The bug is a pre-authentication SQL injection.
infrastructure
8.1
The vulnerability in question is
CVE-2026-48842
(CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.
threat_actor
Winter Vivern
Roundcube security flaws have been a popular target for both cybercrime and state-backed hacking groups, with the Winter Vivern (TA473) Russian threat group exploiting a cross-site scripting (XSS) zero-day (CVE-2023-5631) in
attacks targeting European government entities
and the Russian APT28 cyber-espionage group abusing multiple flaws (CVE-2020-35730, CVE-2020-12641, and CVE-2021-44026)
to breach Ukrainian government email systems
.
threat_actor
APT28
Roundcube security flaws have been a popular target for both cybercrime and state-backed hacking groups, with the Winter Vivern (TA473) Russian threat group exploiting a cross-site scripting (XSS) zero-day (CVE-2023-5631) in
attacks targeting European government entities
and the Russian APT28 cyber-espionage group abusing multiple flaws (CVE-2020-35730, CVE-2020-12641, and CVE-2021-44026)
to breach Ukrainian government email systems
.
organisation
IMAP
Roundcube Webmail is a browser-based IMAP email client used as the default mail interface by thousands of services with millions of users, and it is pre-installed with the widely used cPanel web hosting control panel.
organisation
cPanel
Roundcube Webmail is a browser-based IMAP email client used as the default mail interface by thousands of services with millions of users, and it is pre-installed with the widely used cPanel web hosting control panel.
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, CVE-2026-48842)
organisation
PHP
The plugin performs database lookups that map email addresses to mailbox usernames and uses PHP’s
preg_replace()
function with backslash escaping to try to prevent SQL injection.
organisation
the Cyber Centre
In an update shared this week, the Cyber Centre
said
the security flaw is being actively exploited in the wild, citing open-source reporting.
organisation
NFL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Tactical Metrics
Metrics
infrastructure
Roundcube
Affected Product
Click for context!
In July, Proofpoint
reported
activity by a suspected China-nexus actor tracked as UNK_MassTraction, which exploited known Roundcube vulnerabilities to deploy web shells or VShell, a post-exploitation tool.
Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild.
Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild
Pierluigi Paganini
September 28, 2026
Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild, putting unpatched webmail servers at risk of database compromise.
A Roundcube Webmail vulnerability, tracked as CVE-2026-48842 (CVSS score of 8.1) and patched four months ago, is now being exploited in the wild.
The vulnerability CVE-2026-48842 affects Roundcube 1.6.x versions before 1.6.16 and 1.7.x versions before 1.7.1, but there’s an important detail: the vulnerable code sits in the
virtuser_query
plugin.
Roundcube released the fixes on May 24, 2026.
That gives an unauthenticated attacker a direct path to the database behind Roundcube.
This means an attacker does not need to authenticate to access the database behind Roundcube.
“Unauthenticated attackers can inject SQL into Roundcube’s database backend through the virtuser_query plugin, potentially exposing mail account credentials and stored messages.”
warns SentinelOne
.
Roundcube is an email application, and its database can contain information that becomes extremely useful once an attacker gets access to it.
Roundcube fixed the problem in May, but the exploitation warning arrived in September.
Threat actors have targeted multiple Roundcube flaws in attacks in the past.
In February, CISA listed
CVE-2025-49113
and
CVE-2025-68461
as actively exploited Roundcube vulnerabilities.
Roundcube has repeatedly appeared in attacks where a public-facing mail interface provides an initial point of access.
For defenders, the first step is to check which Roundcube versions are running.
However, this should not replace updating Roundcube.
Organizations with exposed Roundcube servers should therefore review application logs for signs of exploitation.
In July 2026, Proofpoint said it identified a suspected China-aligned adversary dubbed
UNK_MassTraction
exploiting known security flaws in Roundcube to deliver web shells or a post-exploitation tool called VShell.
Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild.
Ravie Lakshmanan
Sep 25, 2026
Vulnerability / Email Security
The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild.
The vulnerability in question is
CVE-2026-48842
(CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.
"Unauthenticated attackers can inject SQL into Roundcube's database backend through the virtuser_query plugin, potentially exposing mail account credentials and stored messages," SentinelOne
said
.
Patches for the vulnerability were
released
by Roundcube in May 2026 as part of 1.6.16 and 1.7.1.
Data from the Shadowserver Foundation shows that there are
more than 523,000 Roundcube instances
exposed to the internet, with 10 of them
flagged
as vulnerable hosts as of September 23, 2026.
Vulnerabilities in Roundcube have been an attractive target for threat actors looking to harvest sensitive email communications.
Roundcube security flaws have been a popular target for both cybercrime and state-backed hacking groups, with the Winter Vivern (TA473) Russian threat group exploiting a cross-site scripting (XSS) zero-day (CVE-2023-5631) in
attacks targeting European government entities
and the Russian APT28 cyber-espionage group abusing multiple flaws (CVE-2020-35730, CVE-2020-12641, and CVE-2021-44026)
to breach Ukrainian government email systems
.
More recently, in February, the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
flagged two other Roundcube flaws
(CVE-2025-49113 and CVE-2025-68461) as actively exploited and ordered government agencies to secure their networks within three weeks.
Hackers now exploit critical Roundcube flaw in code injection attacks.
A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security.
Roundcube Webmail is a browser-based IMAP email client used as the default mail interface by thousands of services with millions of users, and it is pre-installed with the widely used cPanel web hosting control panel.
In May, the Roundcube security team
patched the flaw
(tracked as
CVE-2026-48842
), describing it as a pre-authenticated SQL injection in the virtuser_query built-in plugin, which handles database-driven user lookups and maps users to email addresses.
Successful exploitation can let threat actors with no privileges bypass authentication, inject and execute malicious database commands, and steal data from Roundcube's database in high-complexity attacks that don't require user interaction.
Roundcube also "strongly" recommended that users update their servers to versions 1.6.16 and 1.7.1, which address this vulnerability.
Threat monitoring non-profit Shadowserver
now tracks over 523,000 Roundcube instances
exposed on the Internet.
Roundcube instances exposed online
Since May 2022, the cybersecurity agency
has tagged 11 Roundcube Webmail vulnerabilities
as exploited in the wild.
Metrics
infrastructure
1.6
Software Version
The vulnerability CVE-2026-48842 affects Roundcube 1.6.x versions before 1.6.16 and 1.7.x versions before 1.7.1, but there’s an important detail: the vulnerable code sits in the
virtuser_query
plugin.
The vulnerability in question is
CVE-2026-48842
(CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.
Metrics
infrastructure
1.6.16
Software Version
The vulnerability CVE-2026-48842 affects Roundcube 1.6.x versions before 1.6.16 and 1.7.x versions before 1.7.1, but there’s an important detail: the vulnerable code sits in the
virtuser_query
plugin.
Versions older than 1.6.16 or 1.7.1 should be considered vulnerable.
The vulnerability in question is
CVE-2026-48842
(CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.
Patches for the vulnerability were
released
by Roundcube in May 2026 as part of 1.6.16 and 1.7.1.
Roundcube also "strongly" recommended that users update their servers to versions 1.6.16 and 1.7.1, which address this vulnerability.
Metrics
infrastructure
1.7
Software Version
The vulnerability CVE-2026-48842 affects Roundcube 1.6.x versions before 1.6.16 and 1.7.x versions before 1.7.1, but there’s an important detail: the vulnerable code sits in the
virtuser_query
plugin.
The vulnerability in question is
CVE-2026-48842
(CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.
Metrics
infrastructure
1.7.1
Software Version
The vulnerability CVE-2026-48842 affects Roundcube 1.6.x versions before 1.6.16 and 1.7.x versions before 1.7.1, but there’s an important detail: the vulnerable code sits in the
virtuser_query
plugin.
Versions older than 1.6.16 or 1.7.1 should be considered vulnerable.
The vulnerability in question is
CVE-2026-48842
(CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.
Patches for the vulnerability were
released
by Roundcube in May 2026 as part of 1.6.16 and 1.7.1.
Roundcube also "strongly" recommended that users update their servers to versions 1.6.16 and 1.7.1, which address this vulnerability.
Metrics
infrastructure
8.1
Software Version
The vulnerability in question is
CVE-2026-48842
(CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.
Intelligence Sources
BleepingComputer
2026-09-24
The Hacker News
2026-09-25
Security Affairs
2026-09-28
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-09-28T10:30
Comprehensive Tactical Telemetry
Highly Correlated Entities
13x
organisation
Identified Entity
VShell
entity
10x
timeline
Temporal Reference
September 28, 2026
date
7x
vulnerability
Exploited CVE
CVE-2026-48842
cve
5x
infrastructure
Software Version
1.6
version
5x
attribution
Attributing Entity
CISA
authority
2x
source region
Origin Country
China
country
2x
target region
Target Country
Canada
country
2x
threat actor
APT Group
Winter Vivern
actor
Contextual Telemetry
Context Block
10 METRICS
infrastructure
Affected Product
Roundcube
software
vulnerability
CVSS Score
8
score
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
general metric
Sep
25
sep
general metric
Score
8
score
general metric
Roundcube Instances
523,000
roundcube instances
general metric
Internet
10
internet
industry
Targeted Sector
Government
sector
tactic
Cyber Operation Type
Espionage
tactic
general metric
Roundcube Webmail
11
roundcube webmail
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.