MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-25 · via The Hacker News

Roundcube Webmail SQL Injection Bug Exploited Before Patch

Image via The Hacker News
Image via The Hacker News

Canada's cyber security center warned that attackers are actively exploiting a patched Roundcube Webmail flaw. The vulnerability, CVE-2026-48842, is a pre-authentication SQL injection in the virtuser_query plugin with a CVSS score of 8.1. It affects versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.

Expanded Detail

Canada’s cyber security center has warned that the Roundcube Webmail vulnerability CVE-2026-48842 was being exploited by attackers. The issue is a pre-authentication SQL injection in the virtuser_query plugin, and it carries a CVSS score of 8.1.

The affected releases are Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1. A patch exists, but exploitation occurred before it was available, according to the warning.

Context

Organizations and individuals using affected Roundcube Webmail versions could be exposed if systems remain unpatched. Because the flaw is pre-authentication, attackers may reach the vulnerable plugin without valid credentials, potentially compromising email-related data or service integrity. Administrators may need to prioritize updates, while users could face reduced trust in webmail communications if exploitation succeeds. The warning highlights how quickly known flaws can be weaponized before defenses are applied.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at The Hacker News →
Related stories
Critical Next.js Vulnerability Allows Remote Code Execution · Cybersecurity
ServiceNow Releases Fixes for Five AI Platform Vulnerabilities · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild.” Browse more stories.