Critical Roundcube Webmail Flaw Exploited in Code Injection Attacks, Thousands of Users at Risk
Hackers have started exploiting a high-severity vulnerability in Roundcube Webmail, a widely used browser-based email client, to carry out code injection attacks. The flaw, patched in May but now actively exploited, allows attackers with no privileges to bypass authentication and inject malicious database commands. This can result in data theft from the email service’s database.
Roundcube is pre-installed on thousands of servers, including those using the popular cPanel web hosting control panel, serving millions of users worldwide. The vulnerability, tracked as CVE-2026-48842, affects versions 1.5 and earlier, and was described by Roundcube’s security team as a “pre-authenticated SQL injection” in the virtuser_query plugin. This plugin handles database-driven user lookups and maps users to email addresses.
Successful exploitation can lead to attackers injecting and executing malicious database commands without requiring user interaction. They can also steal data from the email service’s database in high-complexity attacks. Roundcube strongly recommended that users update their servers to versions 1.6.16 and 1.7.1, which address this vulnerability.
However, there are over 523,000 Roundcube instances exposed on the Internet, according to threat monitoring non-profit Shadowserver. Unfortunately, it’s unclear how many of these instances are honeypots or have already been patched against this flaw. The Canadian Centre for Cyber Security has warned that attackers are now actively exploiting CVE-2026-48842 and urged administrators to secure their webmail servers.
For those who cannot immediately upgrade their servers, the recommendation is to disable or remove the virtuser_query plugin to eliminate the attack vector. This comes as no surprise, given Roundcube’s history of security flaws being exploited by both cybercrime and state-backed hacking groups. In recent months, there have been several high-profile attacks targeting European government entities and Ukrainian government email systems using vulnerabilities in Roundcube.
The exploitation of this critical flaw serves as a stark reminder of the importance of timely patching and regular updates to prevent such attacks. As the cybersecurity landscape continues to evolve, it’s crucial for administrators to stay vigilant and ensure that their webmail servers are secure against emerging threats.
Source: Bleeping Computer — 2026-09-24