Hackers actively exploit critical Roundcube pre-auth SQL injection flaw
Live attacks on the widely exposed Roundcube webmail platform raise the urgency of patching or disabling the vulnerable plugin.
A critical SQL injection vulnerability in Roundcube Webmail (CVE-2026-48842), patched in May, is now being used in real-world attacks, prompting fresh warnings to administrators. The flaw is pre-auth and sits in the virtuser_query plugin, allowing attackers to bypass login, run arbitrary SQL queries, and steal data from Roundcube databases. Roundcube advised upgrading to versions 1.6.16 or 1.7.1 to fully remediate the issue. For operators who cannot patch immediately, disabling or removing the virtuser_query plugin is recommended as a temporary mitigation. The risk is broad because more than 523,000 Roundcube instances are exposed online, and Roundcube bugs have repeatedly been weaponized by both criminal and state-backed actors in recent years.
Why it matters
Real-world exploitation of this bug turns a theoretical risk into an immediate problem for operators of the more than 523,000 Roundcube systems exposed online. Because attackers can bypass login and run arbitrary SQL queries against Roundcube databases, compromised servers risk email data theft until they are upgraded to the fixed versions or the vulnerable plugin is disabled as advised.
Signal or noise?
Does this story matter, or is it hype? Decide before you see what everyone else thinks.
Sources
- BleepingComputer