Actors
Malware
Campaigns
CVEs
Feed
Blog
Home
/
CVEs
/
CVE-2023-5631
CVE
CVE-2023-5631
View on NVD ↗
Stored XSS vulnerability in Roundcube
Source Articles
Hackers now exploit critical Roundcube flaw in code injection attacks
A critical pre-authenticated SQL injection vulnerability in Roundcube Webmail, tracked as CVE-2026-48842, is now being actively exploited in the wild. The flaw exists in the virtuser_query plugin and allows unauthenticated attackers to bypass authentication, execute malicious database commands, and steal data without user interaction. The Canadian Centre for Cyber Security has issued an updated advisory warning of ongoing exploitation, urging administrators to update to patched versions 1.6.16 or 1.7.1, or disable the vulnerable plugin if immediate patching is not possible. Roundcube instances have been frequent targets in the past, including by state-backed groups such as APT28 and TA473.
bleeping-computer
Sep 24, 2026