MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-24 · via BleepingComputer

Roundcube Webmail Vulnerability Under Active Attack, Canadian Cyber Center Warns

Image via BleepingComputer
Image via BleepingComputer

A high-severity SQL injection flaw in Roundcube Webmail, patched in May, is now being actively exploited. The vulnerability allows unauthenticated attackers to bypass authentication and execute database commands. Admins are urged to update or disable the virtuser_query plugin.

Expanded Detail

The flaw affects the virtuser_query plugin, which maps users to email addresses through database lookups. Shadowserver's tracking shows over 523,000 Roundcube installations exposed online, though this figure includes honeypots and already-patched servers. The attack requires no user interaction but is rated high-complexity, and successful exploitation can grant unauthenticated access to the underlying database.

Roundcube has faced repeated targeting from both criminal and state-sponsored actors. Winter Vivern previously exploited an XSS zero-day against European government targets, while APT28 leveraged three separate flaws to compromise Ukrainian government mail systems. CISA has now flagged 11 Roundcube vulnerabilities as exploited since May 2022, with two additional flaws added in February.

Context

Because Roundcube ships with cPanel, millions of users across hosting providers could face mailbox compromise, credential theft, or data exposure if administrators fail to patch promptly. Government and enterprise email systems appear especially vulnerable given the pattern of state-backed exploitation. Organizations unable to update immediately may need to disable the plugin, which could disrupt legitimate mail routing. The recurring targeting suggests webmail platforms remain a persistent weak point in organizational security.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
WordPress zero-day under active attack as exploit chain moves to file writes · Cybersecurity
CISA Adds TeamCity Flaw to KEV as Ransomware Gangs Join Exploitation · Cybersecurity
Check Point rushes hotfix for critical management server flaw under active exploitation · Cybersecurity
Critical WordPress Vulnerability Under Active Attack Immediately After Disclosure · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Hackers now exploit critical Roundcube flaw in code injection attacks.” Browse more stories.