{"id":3154,"date":"2026-09-25T10:24:37","date_gmt":"2026-09-25T10:24:37","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=3154"},"modified":"2026-09-25T10:24:37","modified_gmt":"2026-09-25T10:24:37","slug":"roundcube-pre-auth-sql-injection-flaw-actively-exploited-in-the-wild","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=3154","title":{"rendered":"Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Sep 25, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Email Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh8MACS_IO_gIvzTjppTIaHyXZKPha3ZR13_sXQS7u9Ajphpz-FRL5GNIQzhpbveUPPLuMCq72MYNtdX5o6gF-9MZZg4rPF7mbOP_pjSXyTVOFy3XtzlQiMH6sIdTdsqgZpgQf-yZmk688M6BiOWdUNYZswJVQETAInFkZVZCl99ZoYoGhhgtpJZ0hs9JmV\/s1700-nu-rw-lo-l85-e365\/roundcube.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild.<\/p>\n<p>The vulnerability in question is <strong>CVE-2026-48842<\/strong> (CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.<\/p>\n<p>The issue stems from a preg_replace() backslash escape bypass that allows attackers to inject arbitrary SQL statements without authentication.<\/p>\n<p>\u00abUnauthenticated attackers can inject SQL into Roundcube&#8217;s database backend through the virtuser_query plugin, potentially exposing mail account credentials and stored messages,\u00bb SentinelOne <a href=\"https:\/\/www.sentinelone.com\/vulnerability-database\/cve-2026-48842\/\" target=\"_blank\">said<\/a>.<\/p>\n<p>Patches for the vulnerability were <a href=\"https:\/\/roundcube.net\/news\/2026\/05\/24\/security-updates-1.6.16-and-1.7.1\" target=\"_blank\">released<\/a> by Roundcube in May 2026 as part of 1.6.16 and 1.7.1.<\/p>\n<p>In an update shared this week, the Cyber Centre <a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts-advisories\/roundcube-security-advisory-av26-503\" target=\"_blank\">said<\/a> the security flaw is being actively exploited in the wild, citing open-source reporting. No additional details of the exploitation activity have been disclosed.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/enterprise-ai-security-a\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhgJrVTpy3T5kJ7VEIro3XfMOmfqDnBU03fYT5CyFWrs2rE9BeQxs835FAS_f1yivzd7mZ7KartftPk4qs8w5Br-WzfYMXruXDQk4FiuXcvSxoA4XH93ipwJJyy2Hbs9jqs-keS9KZhCnQ2YYdv93M51kxJlE862ob-RrrEhP4DEVP3E79zMMPf43e5keoK\/s728-nu-rw-lo-l85-e365\/AI-eBook-d-2.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Data from the Shadowserver Foundation shows that there are <a href=\"https:\/\/dashboard.shadowserver.org\/statistics\/iot-devices\/time-series\/?date_range=7&amp;vendor=roundcube&amp;type=mail&amp;model=roundcube&amp;dataset=count&amp;limit=100&amp;group_by=geo&amp;stacking=stacked&amp;auto_update=on\" target=\"_blank\">more than 523,000 Roundcube instances<\/a> exposed to the internet, with 10 of them <a href=\"https:\/\/dashboard.shadowserver.org\/statistics\/combined\/time-series\/?date_range=7&amp;source=http_vulnerable&amp;source=http_vulnerable6&amp;tag=roundcube%2B&amp;dataset=unique_ips&amp;limit=100&amp;group_by=geo&amp;stacking=stacked&amp;auto_update=on\" target=\"_blank\">flagged<\/a> as vulnerable hosts as of September 23, 2026.<\/p>\n<p>Vulnerabilities in Roundcube have been an attractive target for threat actors looking to harvest sensitive email communications. In July 2026, Proofpoint said it identified a suspected China-aligned adversary dubbed UNK_MassTraction exploiting known security flaws in Roundcube to deliver web shells or a post-exploitation tool called VShell.<\/p>\n<p>Way back in February 2026, two other vulnerabilities in the same product (CVE-2025-49113 and CVE-2025-68461) were tagged as actively exploited by the U.S. Cybersecurity and Infrastructure Security Agency (CISA).<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Sep 25, 2026Vulnerability \/ Email Security The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild. The vulnerability&hellip;<\/p>\n","protected":false},"author":1,"featured_media":3155,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[201,128,70,525,1040,202,562,656],"class_list":["post-3154","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-actively","tag-exploited","tag-flaw","tag-injection","tag-preauth","tag-roundcube","tag-sql","tag-wild"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3154","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3154"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3154\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/3155"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3154"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3154"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3154"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}