Roundcube Webmail is a browser-based IMAP email client used as the default mail interface by thousands of services with millions of users, and it is pre-installed with the widely used cPanel web hosting control panel.
The Roundcube security team patched the flaw in May, describing it as a pre-authenticated SQL injection in the virtuser_query built-in plugin, which handles database-driven user lookups and maps users to email addresses. Successful exploitation can let threat actors with no privileges bypass authentication, inject and execute malicious database commands, and steal data from Roundcube's database in high-complexity attacks that don't require user interaction. Roundcube "strongly" recommended that users update to versions 1.6.16 and 1.7.1.
On Monday, four months after the patch was released, the Canadian Centre for Cyber Security updated its May advisory to warn that attackers are now actively exploiting the flaw. "Open-source reporting indicates that CVE-2026-48842 is being exploited in the wild," the Cyber Center warned, urging administrators to secure their webmail servers. For administrators who cannot immediately upgrade, the agency recommends disabling or removing the virtuser_query plugin to eliminate the attack vector.
Threat monitoring non-profit Shadowserver now tracks over 523,000 Roundcube instances exposed on the Internet, though there is no information on how many are honeypots or have already been patched.
Roundcube security flaws have been a popular target for both cybercrime and state-backed hacking groups. The Winter Vivern (TA473) Russian threat group previously exploited a cross-site scripting zero-day (CVE-2023-5631) in attacks targeting European government entities, and the Russian APT28 cyber-espionage group abused multiple flaws to breach Ukrainian government email systems.