Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild
Summary
A pre-authentication SQL injection vulnerability in the Roundcube Webmail virtuser_query plugin, identified as CVE-2026-48842, is being actively exploited in the wild. The Canadian Centre for Cyber Security has issued a warning about this flaw, which affects versions prior to 1.6.16 and 1.7.1. The vulnerability is due to an issue with the preg_replace() function.
IFF Assessment
The discovery and active exploitation of a critical vulnerability in a widely used webmail client pose a significant threat to users and organizations, enabling attackers to compromise systems.
Severity
Defender Context
Defenders need to ensure their Roundcube Webmail installations are updated to the patched versions to mitigate the risk of this actively exploited SQL injection vulnerability. Organizations should monitor for any signs of compromise related to this CVE and review their web application security practices.