Canadian Centre for Cyber Security warns of Roundcube vulnerability exploitation
Summary
Threat actors are currently exploiting a high-severity SQL injection vulnerability, tracked as CVE-2026-48842, in Roundcube, an open-source webmail client, according to the Canadian Centre for Cyber Security. The vulnerability is located in the virtuser_query plugin and can be manipulated without authentication, allowing attackers to interfere with database operations and access sensitive user information. Roundcube has addressed this issue in its versions 1.6.16 and 1.7.1, which were released in late May, but with over 500,000 Roundcube servers exposed on the internet, the extent of the vulnerability remains uncertain. Historically, Roundcube servers have been frequent targets for similar vulnerabilities, highlighting ongoing risks in these systems.