The Canadian Centre for Cyber Security says attackers are actively exploiting CVE-2026-48842, a high-severity Roundcube Webmail SQL injection flaw patched in May. Administrators are urged to update to Roundcube 1.6.16 or 1.7.1, or disable the virtuser_query plugin if they cannot patch immediately. #Roundcube #CVE-2026-48842 #CanadianCentreForCyberSecurity
Keypoints
- CVE-2026-48842 is a pre-authenticated SQL injection flaw in Roundcubeβs virtuser_query plugin.
- Successful exploitation can bypass authentication and enable malicious database commands.
- The Canadian Centre for Cyber Security says the flaw is now being actively exploited in the wild.
- Admins should upgrade to Roundcube 1.6.16 or 1.7.1 to block the attacks.
- If patching is delayed, removing or disabling virtuser_query is recommended.