Canada Warns of Exploitation of Roundcube Webmail Vulnerability
The Canadian Centre for Cyber Security warned that CVE-2026-48842 in Roundcube Webmail is being actively exploited, according to publicly available reports. Patches have been available since May.

Roundcube CVE-2026-48842 is being actively exploited in the wild, according to an advisory from the Canadian Centre for Cyber Security. On September 21, 2026, the Canadian center updated advisory AV26-503 and urged administrators of Roundcube webmail servers to deploy patches. This is a pre-authentication SQL injection vulnerability in the virtuser_query plugin, meaning the attack does not require logging in to webmail.
The vulnerability affects Roundcube 1.6.x branches before version 1.6.16 and 1.7.x branches before version 1.7.1. The Roundcube project released fixes on May 24, 2026. Newer security releases, 1.6.19 and 1.7.4, have since been released.
What Is Roundcube CVE-2026-48842?
CVE-2026-48842 is an SQL injection vulnerability in the virtuser_query plugin. It is caused by the ability to bypass backslash escaping when using the preg_replace() function. In affected configurations, this could allow an attacker to insert unwanted SQL commands without prior authentication.
SQL injection poses a risk primarily to database data used or processed by webmail. However, the specific scope of possible consequences depends on the server’s deployment and configuration. The Canadian center did not publish technical indicators of compromise or specific attack scenarios.
Canadian Warning Refers to Reported Exploitation
The Canadian Centre for Cyber Security says the active exploitation is based on open-source reports. The warning does not attribute the activity to any specific group, campaign, or attacker. There is also no independent confirmation of the number of attacked servers, compromised organizations, or any potential data acquisition.
Secondary reporting cited more than 523,000 internet-accessible Roundcube instances. However, this figure does not indicate how many systems use the virtuser_query plugin or how many instances run vulnerable versions.
What Roundcube Administrators Should Do
Administrators should verify the Roundcube branch and version in use, as well as whether their deployment uses the virtuser_query plugin. The minimum fix is to update to version 1.6.16 in the 1.6.x branch or 1.7.1 in the 1.7.x branch.
Because Roundcube has since released additional security updates, deploying the current supported version in the branch being used is advisable: 1.6.19 or 1.7.4. Organizations should also monitor further announcements from the Roundcube project, national CERT teams, and trusted security researchers.
- Roundcube 1.6.x: releases before 1.6.16 are vulnerable; the newer security release is 1.6.19.
- Roundcube 1.7.x: releases before 1.7.1 are vulnerable; the newer security release is 1.7.4.
- Publicly accessible webmail servers with the virtuser_query plugin enabled should be prioritized.
Further developments will show whether indicators of compromise, details about affected configurations, or more reliable data on the scope of the attacks will be published. For now, the main confirmation is that fixes exist for the vulnerability and that the Canadian center has labeled it actively exploited based on public reports.
Sources
- Canadian Centre for Cyber Security — Roundcube security advisory AV26-503, Update 1 – Confirms the September 21, 2026 update and the warning that CVE-2026-48842 is being actively exploited according to open-source reports; links to the fixed releases.
- Roundcube Webmail releases – Confirms that releases 1.6.16 and 1.7.1 fixed the pre-authentication SQL injection in virtuser_query, and that versions 1.6.19 and 1.7.4 were released later.
- GitHub Advisory Database — CVE-2026-48842 – Lists the affected branches, fixed-version thresholds, and a technical description of the vulnerability involving a preg_replace() backslash escape bypass.
- BleepingComputer – Independently documents current reporting on the Canadian center’s warning and the context of publicly accessible instances; however, it does not confirm the scope of the impact.
Verified and updated: 09/25/2026 15:21



