Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild
Brief
The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild.
The vulnerability in question is CVE-2026-48842 (CVSS score: 8. 1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.
- x before 1.
- 16 and 1.
- x before 1.
- 1.
The issue stems from a preg_replace() backslash
