News

Attackers Are Exploiting a Pre-Auth Roundcube SQL Injection Across Half a Million Mail Servers

Attackers are exploiting CVE-2026-48842, a pre-auth SQL injection in Roundcube patched in May, while more than 500,000 Roundcube servers sit exposed on the internet.

Attackers Are Exploiting a Pre-Auth Roundcube SQL Injection Across Half a Million Mail Servers

Attackers are exploiting a Roundcube webmail flaw that lets them reach the mail database without logging in. The bug was patched in May, but plenty of servers never got the update.

The Canadian Centre for Cyber Security warned this week that "open-source reporting indicates that CVE-2026-48842 is being exploited in the wild," SecurityWeek reports. The agency did not name campaigns, attackers, or victims.

A backslash beats the filter

The flaw, rated CVSS 8.1, sits in Roundcube's virtuser_query plugin, which maps email addresses to mailbox usernames. The plugin tries to sanitize input with preg_replace() and backslash escaping.

According to SentinelOne's analysis, crafted backslash sequences defeat that escaping, so quote characters end up inside the SQL string sent to the database. No credentials are required.

A successful attack can tamper with database operations and expose user identities, messages, and address books. It can also help attackers map authentication workflows and admin functions for a deeper intrusion.

Half a million doors on the internet

Shadowserver counts more than 500,000 Roundcube servers reachable from the internet. That is exposure, not a vulnerability count, and nobody has published how many are still unpatched.

The fix shipped in Roundcube 1.6.16 and 1.7.1 in late May. Self-hosted admins have to apply it themselves, while customers of hosting providers depend on their provider to do it.

Roundcube is a repeat target. Earlier bugs such as CVE-2025-49113, CVE-2025-68461, and CVE-2024-37383 all drew attackers, and BleepingComputer is tracking the new exploitation too. The pattern looks like other patched-but-exposed edge software, from WatchGuard Firebox to TeamCity, where the months between fix and deployment are the real attack window.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free