Roundcube Webmail released urgent security updates to fix multiple high-risk vulnerabilities across supported branches, including versions 1.6.16 and 1.7.1, following earlier fixes in 1.6.14 for the 1.6.x line. The newly disclosed issues include CVE-2026-48842, a pre-authentication SQL injection flaw in the virtuser_query plugin with a CVSS score of 8.1, and CVE-2026-48844, a code injection bug tied to direct code evaluation in LDAP autovalues configuration that could enable arbitrary command execution. Additional patches address XSS, session poisoning, arbitrary file deletion, and SSRF bypass vulnerabilities tracked as CVE-2026-48845 through CVE-2026-48849, and a dCERT advisory also lists Roundcube as affected by multiple vulnerabilities.
Earlier Roundcube fixes had already addressed a separate set of severe weaknesses, including a pre-authentication arbitrary file write issue in Redis and Memcached session handlers that could lead to unauthenticated remote code execution and full server compromise, along with account takeover, SSRF, IMAP injection, CSRF bypass, and HTML attachment preview XSS. Researchers credited across the disclosures include y0us, Georgios Tsimpidas, flydragon777, the Martila Security Research Team, aikido_security, and nullcathedral. Roundcube described the releases as stable and urged administrators to back up systems and deploy updates quickly to protect exposed email infrastructure from pre-authentication exploitation.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
The Roundcube development team released urgent security updates in versions 1.6.16 and 1.7.1 to remediate multiple high-risk vulnerabilities. These included CVE-2026-48842, a pre-authentication SQL injection flaw in the virtuser_query plugin, CVE-2026-48844 for code injection via LDAP autovalues, and additional XSS, session poisoning, arbitrary file deletion, and SSRF bypass issues.
dCERT published Advisory 2026-1644 covering multiple vulnerabilities in Roundcube Webmail. The reference provides the advisory publication as a dated milestone in the disclosure timeline.
Roundcube published its vendor announcement for security updates 1.6.16 and 1.7.1, marking the release of fixes for multiple high-risk vulnerabilities in the webmail software. The announcement establishes 2026-05-24 as the dated release milestone for these updates.
Roundcube Webmail released version 1.6.14 for the 1.6.x branch to fix multiple severe vulnerabilities, including a pre-authentication arbitrary file write issue that could lead to remote code execution, along with SSRF, account takeover, IMAP injection, CSRF bypass, and XSS issues. The project urged administrators to update production deployments promptly and back up database and application data before upgrading.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesecurityonline.info
Open sourcedcert.de
Open sourceroundcube.net
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.