Roundcube Webmail Vulnerability Under Active Attack, Canadian Cyber Center Warns

A high-severity SQL injection flaw in Roundcube Webmail, patched in May, is now being actively exploited. The vulnerability allows unauthenticated attackers to bypass authentication and execute database commands. Admins are urged to update or disable the virtuser_query plugin.
The flaw affects the virtuser_query plugin, which maps users to email addresses through database lookups. Shadowserver's tracking shows over 523,000 Roundcube installations exposed online, though this figure includes honeypots and already-patched servers. The attack requires no user interaction but is rated high-complexity, and successful exploitation can grant unauthenticated access to the underlying database.
Roundcube has faced repeated targeting from both criminal and state-sponsored actors. Winter Vivern previously exploited an XSS zero-day against European government targets, while APT28 leveraged three separate flaws to compromise Ukrainian government mail systems. CISA has now flagged 11 Roundcube vulnerabilities as exploited since May 2022, with two additional flaws added in February.
Because Roundcube ships with cPanel, millions of users across hosting providers could face mailbox compromise, credential theft, or data exposure if administrators fail to patch promptly. Government and enterprise email systems appear especially vulnerable given the pattern of state-backed exploitation. Organizations unable to update immediately may need to disable the plugin, which could disrupt legitimate mail routing. The recurring targeting suggests webmail platforms remain a persistent weak point in organizational security.