US Edition
Your source for latest news
TechnologyCybersecurity

Canada Warns Hackers Are Actively Exploiting a Roundcube Webmail Flaw Patched Months Ago

Canada's cyber agency says a critical, unauthenticated flaw in the open-source email platform used by governments, universities and internet providers is now being exploited in the wild, four months after a fix became available.

PT
By PressTemps Technology DeskPublished Today, 05:47 ET · 5 min read
Canada Warns Hackers Are Actively Exploiting a Roundcube Webmail Flaw Patched Months Ago
The Roundcube Webmail interface, the open-source email platform at the center of the newly exploited flaw. Photo: VulcanSphere / Wikimedia Commons, CC BY-SA 3.0
What to know
Canada's Centre for Cyber Security confirmed on September 21 that CVE-2026-48842, a pre-authentication SQL injection flaw in Roundcube Webmail, is being exploited in the wild.
The flaw is rated 8.1 out of 10 in severity and affects Roundcube versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1; a patch has been available since May 24, 2026.
Roundcube is widely bundled into hosting control panels used by governments, universities and internet providers, and has previously been targeted by state-linked hacking groups including APT28 and Winter Vivern.
CISA's Known Exploited Vulnerabilities catalog already lists eleven earlier Roundcube flaws, and researchers say this one could be added soon, which would set a mandatory patch deadline for U.S. federal agencies.

Canada's national cybersecurity agency has confirmed that hackers are actively exploiting a critical, unauthenticated flaw in Roundcube Webmail, the open-source email platform used by government agencies, universities and internet service providers around the world to run their own mail servers. The warning arrives roughly four months after a patch for the flaw was made publicly available, underscoring how slowly many organizations apply fixes to widely used server software.

The Canadian Centre for Cyber Security updated an advisory it first issued in May, stating on September 21 that "open-source reporting indicates" the vulnerability, tracked as CVE-2026-48842, "is being exploited in the wild." The agency urged administrators running Roundcube to apply the available security updates "without delay." Independent researchers who track the flaw said in the days that followed that scanning and exploitation attempts were continuing.

The Numbers

The vulnerability carries a severity rating of 8.1 out of 10 on the industry-standard Common Vulnerability Scoring System, according to the National Vulnerability Database, maintained by the National Institute of Standards and Technology. It affects Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the two production branches of the software that most self-hosted mail servers run. Roundcube's development team shipped fixes for those versions, along with six other security issues, in a coordinated release on May 24 — meaning the gap between patch availability and confirmed exploitation stretched to roughly four months.

The flaw sits in a plugin called virtuser_query, which many hosting providers enable to map email addresses to database records before a user logs in. Because the code runs pre-authentication, an attacker needs no valid username or password to trigger it. The bug itself is a sanitization bypass: Roundcube used the PHP function preg_replace() to escape backslash characters in user input before passing it to a database query, and attackers found a way to craft input that slips past that filter and injects raw SQL fragments instead, according to a technical writeup published by the security firm SentinelOne.

"Unauthenticated attackers can inject SQL into Roundcube's database backend through the virtuser_query plugin, potentially exposing mail account credentials and stored messages," SentinelOne's vulnerability database entry for the flaw states.

The exploitation activity was first flagged through honeypot systems — decoy servers designed to attract and log attack traffic — operated by the cyber insurer Coalition, whose researchers observed automated probes attempting to trigger the flaw before the Canadian advisory update was published. That pattern is typical of how mass-exploitation campaigns unfold: once a proof-of-concept technique circulates among researchers or criminal forums, scanning tools sweep the internet for any server still running an unpatched version, with little regard for the size or importance of the target.

How Roundcube Became a Target

Roundcube is one of the most common self-hosted webmail platforms, bundled by default into control panels that internet service providers and web hosts use to offer email service to their customers. That footprint has made it a recurring target for both cybercriminals and government-linked hacking groups. Security researchers have documented Roundcube exploitation over the past several years by APT28, a hacking unit linked to Russian military intelligence also known as BlueDelta or Fancy Bear, against Ukrainian government bodies, and by a separate group known as Winter Vivern against government ministries and think tanks across Central and Eastern Europe, according to an analysis published by the vulnerability-management firm Greenbone. Physics and engineering departments at several North American universities have also been named as past targets. The Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalog now lists eleven separate Roundcube flaws that have been abused in real-world attacks, a tally that predates this latest addition.

That history is part of why the September update carries weight even though the underlying patch is months old. Unpatched, internet-facing software of this kind tends to draw attention from opportunistic scanners as well as more determined intruders once a working exploit begins circulating, and Roundcube's installed base skews toward smaller organizations that may lack dedicated security staff to track every advisory the project publishes — the same team pushed two further rounds of maintenance updates, in July and again on September 6, layering additional fixes on top of the May release.

Who Is Affected, and What Comes Next

Because Roundcube ships inside popular hosting-panel software such as cPanel, Plesk and DirectAdmin, the practical exposure extends well past organizations that consciously chose the platform. Universities, municipal governments, regional internet providers and small and mid-sized businesses that outsource email hosting are all represented among prior victims of Roundcube bugs, according to researchers who have tracked the software's exploitation history. Successful exploitation of this particular flaw is limited to whatever data the webmail server's own database account can reach, which security researchers say typically includes stored mail credentials and message content rather than full control of the underlying server — a narrower outcome than the remote-code-execution bugs Roundcube has suffered in the past, but one that can still hand attackers a foothold for further intrusion or credential theft.

Administrators who have not yet updated are being told to move to Roundcube 1.6.16 or 1.7.1 at minimum, and preferably to the newer 1.6.19 and 1.7.4 maintenance releases the project has since published, or to disable the virtuser_query plugin entirely if their configuration does not require it. Researchers who published technical analyses of the bug also recommended that administrators comb through database and web-server logs for unauthenticated requests carrying malformed backslash sequences, and apply the principle of least privilege to the database accounts Roundcube uses, so that even a successful injection yields an attacker as little access as possible.

The Canadian advisory's escalation from a routine patch notice to a confirmed-exploitation warning also raises the odds that the U.S. Cybersecurity and Infrastructure Security Agency adds CVE-2026-48842 to its Known Exploited Vulnerabilities catalog in the coming days, a step that would impose a fixed remediation deadline on federal civilian agencies still running the software, as it has for eleven earlier Roundcube flaws. For everyone else — the universities, town governments and regional internet providers that make up much of Roundcube's user base — the episode is a reminder that a patch sitting unapplied for months is, in practical terms, no patch at all.

More on this story

All Technology