Close Menu
NCIJ Network NCIJ Network
    What's Hot

    North Sea appraisal ops up the oil & gas discoveries’ projected size

    September 25, 2026

    Thank you, Phil Gates, for nearly 40 years of country diaries | The Guardian

    September 25, 2026

    Angh by Theja Rio at Toronto: The Indian film taking Nagaland to global cinema

    September 25, 2026
    Facebook X (Twitter) Instagram
    Trending
    • North Sea appraisal ops up the oil & gas discoveries’ projected size
    • Thank you, Phil Gates, for nearly 40 years of country diaries | The Guardian
    • Angh by Theja Rio at Toronto: The Indian film taking Nagaland to global cinema
    • ‘Devastating’: council rejects Frome residents’ bid for regeneration project | Regeneration
    • Waymo is scaling fast: Here’s what the fleet data shows
    • The GPU Shortage Inside Your Own Infrastructure: Why AI Workloads Queue While Capacity Sits Idle
    • WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV
    • Jeff Booth: Why $1 Million BTC Is Thinking Too Small
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, September 25
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Roundcube Webmail Vulnerability in Attackers’ Crosshairs

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 25, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Threat actors have been exploiting a high-severity vulnerability in Roundcube, the popular open source webmail client, the Canadian Centre for Cyber Security warns.

    Tracked as CVE-2026-48842 (CVSS score of 8.1), the security defect is described as an SQL injection in the virtuser_query plugin that can be exploited without authentication.

    The plugin resolves email addresses to mailbox usernames and uses the preg_replace() filter with backslash escaping to neutralize injection attempts.

    CVE-2026-48842, however, allows attackers to bypass the protection by using crafted queries containing backslash sequences that defeat the plugin’s regular-expression escaping mechanism.

    The attacker’s malicious input invokes the virtuser_query plugin to traverse the preg_replace() filter, resulting in quote characters being concatenated into an SQL string that is sent to the database, SentinelOne explains.

    Roundcube resolved the vulnerability in versions 1.6.16 and 1.7.1, which were released in late May.

    Advertisement. Scroll to continue reading.

    This week, the Canadian Centre for Cyber Security warned that threat actors have been exploiting it in attacks, but did not share details on the observed exploitation.

    “Open-source reporting indicates that CVE-2026-48842 is being exploited in the wild,” the Cyber Centre said.

    As Paymob information security lead Omar Ahmed points out, successful exploitation of the bug allows attackers to tamper with database operations, access protected information, access user identities, messages, and address books, and map authentication workflows and admin functions.

    Data from the non-profit organization The Shadowserver Foundation shows that there are over 500,000 Roundcube servers accessible from the internet, but it is unclear how many of them are vulnerable.

    Vulnerabilities in Roundcube servers are frequently targeted by threat actors. Some examples include CVE-2025-68461, CVE-2025-49113, and CVE-2024-37383.

    Related: SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted

    Related: Critical WordPress Vulnerability Exploited Immediately After Disclosure

    Related: Adobe Patches Critical Flaws in Connect, AEM Forms

    Related: Check Point Patches Exploited Management Server Zero-Day

    Attackers crosshairs Roundcube Vulnerability Webmail
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV

    Cloudflare Fixes Flaw That Let One Container Read Another Customer’s Leftover Disk Data

    17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360

    New Carbonato malware uses AI agents to hijack exposed Docker hosts

    WordPress patches a critical severity security vulnerability

    Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    North Sea appraisal ops up the oil & gas discoveries’ projected size

    September 25, 2026

    Thank you, Phil Gates, for nearly 40 years of country diaries | The Guardian

    September 25, 2026

    Angh by Theja Rio at Toronto: The Indian film taking Nagaland to global cinema

    September 25, 2026

    ‘Devastating’: council rejects Frome residents’ bid for regeneration project | Regeneration

    September 25, 2026
    Latest Posts

    Spain’s Pedro Sánchez is a progressive outlier in Europe – and over Ceuta, he is being made to pay for it | Eoghan Gilmartin

    August 6, 2026

    Putin Signs Law For Russia To Regulate Crypto Exchanges

    August 6, 2026

    Canadian pleads guilty to Snowflake cloud data-theft attacks

    August 6, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    North Sea appraisal ops up the oil & gas discoveries’ projected size

    September 25, 2026

    Thank you, Phil Gates, for nearly 40 years of country diaries | The Guardian

    September 25, 2026

    Angh by Theja Rio at Toronto: The Indian film taking Nagaland to global cinema

    September 25, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.