Hackers now exploit critical Roundcube flaw in code injection attacks

Hackers now exploit critical Roundcube flaw in code injection attacks
The Canadian Centre for Cyber Security says attackers are actively exploiting CVE-2026-48842, a high-severity Roundcube Webmail SQL injection flaw patched in May. Administrators are urged to update to Roundcube 1.6.16 or 1.7.1, or disable the virtuser_query plugin if they cannot patch immediately. #Roundcube #CVE-2026-48842 #CanadianCentreForCyberSecurity

Keypoints

  • CVE-2026-48842 is a pre-authenticated SQL injection flaw in Roundcube’s virtuser_query plugin.
  • Successful exploitation can bypass authentication and enable malicious database commands.
  • The Canadian Centre for Cyber Security says the flaw is now being actively exploited in the wild.
  • Admins should upgrade to Roundcube 1.6.16 or 1.7.1 to block the attacks.
  • If patching is delayed, removing or disabling virtuser_query is recommended.

Read More: https://www.bleepingcomputer.com/news/security/critical-roundcube-flaw-now-actively-exploited-in-code-injection-attacks/