Trusence Technology, daily
Last updated 26 September 2026 Türkçe
← All stories
Security

Hackers actively exploit critical Roundcube pre-auth SQL injection flaw

Live attacks on the widely exposed Roundcube webmail platform raise the urgency of patching or disabling the vulnerable plugin.

A critical SQL injection vulnerability in Roundcube Webmail (CVE-2026-48842), patched in May, is now being used in real-world attacks, prompting fresh warnings to administrators. The flaw is pre-auth and sits in the virtuser_query plugin, allowing attackers to bypass login, run arbitrary SQL queries, and steal data from Roundcube databases. Roundcube advised upgrading to versions 1.6.16 or 1.7.1 to fully remediate the issue. For operators who cannot patch immediately, disabling or removing the virtuser_query plugin is recommended as a temporary mitigation. The risk is broad because more than 523,000 Roundcube instances are exposed online, and Roundcube bugs have repeatedly been weaponized by both criminal and state-backed actors in recent years.

Why it matters

Real-world exploitation of this bug turns a theoretical risk into an immediate problem for operators of the more than 523,000 Roundcube systems exposed online. Because attackers can bypass login and run arbitrary SQL queries against Roundcube databases, compromised servers risk email data theft until they are upgraded to the fixed versions or the vulnerable plugin is disabled as advised.

Sources

  • BleepingComputer