Critical Roundcube Vulnerability Exploited in Code Injection Attacks, Leaving Millions of Users Exposed
A highly critical vulnerability in the popular webmail client Roundcube is being actively exploited by hackers, putting millions of users at risk. The Canadian Centre for Cyber Security has issued a warning that attackers are now taking advantage of the flaw, which was patched in May but still widely present on the internet.
Roundcube Webmail is used as the default email interface by thousands of services and hosts millions of users. It’s also pre-installed with cPanel, a widely used web hosting control panel. The vulnerability, tracked as CVE-2026-48842, allows threat actors to bypass authentication, inject malicious database commands, and steal data from Roundcube’s database without requiring user interaction.
The bug is a pre-authenticated SQL injection in the virtuser_query plugin, which handles database-driven user lookups and maps users to email addresses. In other words, an attacker can exploit this flaw to inject malicious code into Roundcube’s database, essentially allowing them to access sensitive data with ease.
Shadowserver, a non-profit threat monitoring organization, has identified over 523,000 Roundcube instances exposed on the internet. However, it’s unclear how many of these have already been patched or are honeypots designed to lure in attackers.
The Canadian Centre for Cyber Security is urging administrators to update their servers to versions 1.6.16 and 1.7.1, which address this vulnerability. If immediate updates are not possible, admins should disable or remove the virtuser_query plugin to eliminate the attack vector.
Roundcube’s security flaws have been a popular target for both cybercrime and state-backed hacking groups in recent years. The Winter Vivern threat group exploited a cross-site scripting (XSS) zero-day in attacks targeting European government entities, while APT28 abused multiple flaws to breach Ukrainian government email systems.
This latest development is yet another reminder of the importance of keeping software up-to-date and monitoring for vulnerabilities. With millions of users potentially affected, it’s crucial that administrators take immediate action to secure their webmail servers and prevent these attacks.
If you’re a Roundcube administrator, don’t wait – update your server to the latest version or disable the virtuser_query plugin as soon as possible. Remember, prevention is key in cybersecurity: stay informed, stay vigilant, and protect your users’ sensitive data from would-be attackers.
Source: Bleeping Computer — 2026-09-24