Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

Дата публикации: 25-09-2026 10:14:02

The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild.
The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.
The issue stems from a preg_replace() backslash

Основное содержимое страницы с новостью.

Ravie LakshmananSep 25, 2026Vulnerability / Email Security

The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild.

The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.

The issue stems from a preg_replace() backslash escape bypass that allows attackers to inject arbitrary SQL statements without authentication.

"Unauthenticated attackers can inject SQL into Roundcube's database backend through the virtuser_query plugin, potentially exposing mail account credentials and stored messages," SentinelOne said.

Patches for the vulnerability were released by Roundcube in May 2026 as part of 1.6.16 and 1.7.1.

In an update shared this week, the Cyber Centre said the security flaw is being actively exploited in the wild, citing open-source reporting. No additional details of the exploitation activity have been disclosed.

Data from the Shadowserver Foundation shows that there are more than 523,000 Roundcube instances exposed to the internet, with 10 of them flagged as vulnerable hosts as of September 23, 2026.

Vulnerabilities in Roundcube have been an attractive target for threat actors looking to harvest sensitive email communications. In July 2026, Proofpoint said it identified a suspected China-aligned adversary dubbed UNK_MassTraction exploiting known security flaws in Roundcube to deliver web shells or a post-exploitation tool called VShell.

Way back in February 2026, two other vulnerabilities in the same product (CVE-2025-49113 and CVE-2025-68461) were tagged as actively exploited by the U.S. Cybersecurity and Infrastructure Security Agency (CISA).

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets09.230-09-2026
2SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild06.826-09-2026
3Jetzt updaten! Attacken auf Roundcube-Webmail-Instanzen beobachtet014.7625-09-2026
4Jetzt updaten! Attacken auf Roundcube-Webmail-Instanzen beobachtet014.7625-09-2026
5Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution08.3930-09-2026
6Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link011.5426-09-2026
7Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation09.2627-09-2026
8WordPress CVE-2026-87902 Under Active Attack: Critical RCE Flaw Exploited Within Hours013.5924-09-2026
9Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells09.526-09-2026

Классификация: . Схожих патентов: 0. Схожих новостей: 9. Тональность: 0. Информативность: 10.85. Источник: thehackernews.com.