A critical SQL-injection flaw in Roundcube Webmail's virtuser_query plugin, tracked as CVE-2026-48842, is being actively exploited in the wild. The pre-authentication vulnerability stems from a backslash-escaping bypass in PHP's preg_replace handling and can allow an attacker to manipulate database queries before logging in, provided the vulnerable plugin is enabled and reachable.
The Canadian Centre for Cyber Security cited open-source reporting confirming exploitation and urged organizations to act immediately. Affected deployments include Roundcube versions earlier than 1.6.16 in the 1.6 LTS branch and earlier than 1.7.1 in the 1.7 branch; administrators should update exposed instances, verify whether virtuser_query is enabled, and review web, application, database, and authentication logs for compromise indicators.

See which actors are running it and whether you're in range.
2 events from the most recent confirmed update back to the earliest known activity.
The Canadian Center for Cyber Security updated advisory AV26-503, citing open-source reporting that the pre-authentication SQL-injection flaw CVE-2026-48842 was being actively exploited in the wild.
Roundcube published security advisories addressing multiple flaws in its webmail platform, including remediation for the virtuser_query SQL-injection issue.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.