A Four-Month-Old Roundcube Bug Reaches Active Exploitation
Security / news
A Four-Month-Old Roundcube Bug Reaches Active Exploitation
Canada's Cyber Centre says attackers are using a pre-authentication SQL injection Roundcube patched in May, while the U.S. government's own exploitation tag for the flaw still reads none.

An unauthenticated attacker can run arbitrary SQL against a Roundcube webmail server through its optional virtuser_query plugin, no password required, provided the plugin is enabled, which is common on hosting setups that map several domains to one mailbox backend. Roundcube fixed the bug, tracked as CVE-2026-48842, on May 24, 2026. Four months later, Canada's Communications Security Establishment updated its advisory, AV26-503, on Sept. 21 to say open-source reporting indicates the flaw is being exploited in the wild.
The flaw carries a CVSS score of 8.1, rated High rather than Critical, because exploitation requires network access to a Roundcube instance running the virtuser_query plugin specifically rather than every installation. Omar Ahmed, information security lead at Paymob, told SecurityWeek that successful exploitation lets an attacker "tamper with database operations, access protected information, access user identities, messages, and address books, and map authentication workflows and admin functions." That is a full compromise of the mail backend for any server where the plugin is active, which the score's own preconditions do not convey.
A patch in May, a warning in September
The gap between the fix and the confirmed exploitation warning is the story here, not the bug itself.
| Date | Event |
|---|---|
| May 24, 2026 | Roundcube ships 1.6.16 and 1.7.1, crediting a researcher using the handle skull |
| July 2026 | Proofpoint links a separate Roundcube-targeting campaign to a suspected China-aligned actor it calls UNK_MassTraction |
| Sept. 21, 2026 | Canada's Cyber Centre updates AV26-503 to report active exploitation |
| Sept. 23, 2026 | Shadowserver flags 10 confirmed-vulnerable hosts among more than 523,000 internet-exposed Roundcube instances |
| Sept. 24, 2026 | The flaw's exploitation-status field in the U.S. National Vulnerability Database still reads "none" |
Canada's Sept. 21 update does not name who is behind the current exploitation, unlike the July campaign it distinguishes from this one. Proofpoint has already put a name to that earlier activity, UNK_MassTraction, but neither Proofpoint nor the Cyber Centre has said whether the same group is running the attacks flagged this month.
The score that says High and the tag that says none
The gap in that last row is worth dwelling on. The NVD's own machine-readable exploitation assessment for CVE-2026-48842, generated under the government's Stakeholder-Specific Vulnerability Categorization framework, was last updated Sept. 24 and still lists exploitation as "none," three days after a national cyber agency said the opposite in writing. Neither assessment is wrong on its own terms: the NVD tag reflects what its automated pipeline has ingested as of a timestamp, and Canada's advisory reflects open-source reporting its analysts read directly. The disagreement is a reminder that a CVSS score and an exploitation tag describe a moment, not a guarantee, and that CISA has not added this flaw to its Known Exploited Vulnerabilities catalog even as a peer agency calls it exploited.

What operators can still do
Roundcube's own recommendation has not changed since May: update the long-term-support branch to 1.6.16 or later, or the current branch to 1.7.1 or later, and disable the virtuser_query plugin entirely on any install that does not need domain-to-mailbox mapping. Shadowserver's figures suggest most of the 523,000 exposed instances are not confirmed vulnerable, which points to wide but incomplete patching rather than a mass-unpatched fleet.
Other flaws added to CISA's catalog this month came with sharper federal deadlines, including a double-fetch bug reaching SYSTEM inside Avast's own sandbox and a 9.8-severity flaw in lwIP's MQTT client. Roundcube's flaw has had no such deadline attached, because CISA has not classified it as known-exploited at all.
Sources
More in Security
- 01CISA Gives Agencies 3 Days to Patch an Exploited SharePoint BugMicrosoft rated the flaw a low-risk spoofing issue for 16 days after patching it, and a honeypot logged the first attack four weeks after the correction upgraded it to an 8.8.
- 02CISA Adds a Fourth MikroTrick Bug to Its Exploited ListCVE-2026-67279 joins two other bugs from the same six-flaw MikroTik batch already on CISA's list, but Bishop Fox says it, not the pair flagged in September, is the one that actually opens the door.
- 03OpenClaw's New Scanners Agree on Just 0.69% of Risky SkillsFour audits since February have counted between 341 and 1,467 malicious or flawed skills on ClawHub, and NVIDIA's scanner disagrees with the other two on all but 468 of 67,453 skills checked.
- 04CISA Lists 14 Botslab Dashcam Flaws With No Fix in SightThe worst of the bugs lets a network attacker push firmware with no cryptographic signature onto the device, and Botslab has not told CISA whether it plans to fix any of the 14.