bleeping-computer · Crawled Sep 24, 2026

Hackers now exploit critical Roundcube flaw in code injection attacks

2 Actors 7 CVEs
Read original article ↗

AI Summary

A critical pre-authenticated SQL injection vulnerability in Roundcube Webmail, tracked as CVE-2026-48842, is now being actively exploited in the wild. The flaw exists in the virtuser_query plugin and allows unauthenticated attackers to bypass authentication, execute malicious database commands, and steal data without user interaction. The Canadian Centre for Cyber Security has issued an updated advisory warning of ongoing exploitation, urging administrators to update to patched versions 1.6.16 or 1.7.1, or disable the vulnerable plugin if immediate patching is not possible. Roundcube instances have been frequent targets in the past, including by state-backed groups such as APT28 and TA473.

AI-extracted · verify before operational use

Extracted Entities 9 found

MITRE ATT&CK TTPs 23 techniques