Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Did Milwaukee juvenile homicides increase 57% under David Crowley?

    September 25, 2026

    What Milwaukee can learn from Baltimore’s community policing plan

    September 25, 2026

    Can Michelle Bolsonaro Help Brazil’s Far Right Win Over Women Voters?

    September 25, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Did Milwaukee juvenile homicides increase 57% under David Crowley?
    • What Milwaukee can learn from Baltimore’s community policing plan
    • Can Michelle Bolsonaro Help Brazil’s Far Right Win Over Women Voters?
    • Trump made ‘final decision’ to give Ukraine Patriot licence, Zelensky says
    • Is your Apple Watch 12 or Ultra 4 randomly restarting? Here’s the fix
    • Microsoft: Recent Windows updates cause desktop loading issues
    • Saifedean Ammous: The Bond Crisis & Bitcoin’s Rise As A True Macro Asset
    • These tropical trees breathe at night to survive drought
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, September 25
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 25, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananSep 25, 2026Vulnerability / Email Security

    The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild.

    The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.

    The issue stems from a preg_replace() backslash escape bypass that allows attackers to inject arbitrary SQL statements without authentication.

    “Unauthenticated attackers can inject SQL into Roundcube’s database backend through the virtuser_query plugin, potentially exposing mail account credentials and stored messages,” SentinelOne said.

    Patches for the vulnerability were released by Roundcube in May 2026 as part of 1.6.16 and 1.7.1.

    In an update shared this week, the Cyber Centre said the security flaw is being actively exploited in the wild, citing open-source reporting. No additional details of the exploitation activity have been disclosed.

    Cybersecurity

    Data from the Shadowserver Foundation shows that there are more than 523,000 Roundcube instances exposed to the internet, with 10 of them flagged as vulnerable hosts as of September 23, 2026.

    Vulnerabilities in Roundcube have been an attractive target for threat actors looking to harvest sensitive email communications. In July 2026, Proofpoint said it identified a suspected China-aligned adversary dubbed UNK_MassTraction exploiting known security flaws in Roundcube to deliver web shells or a post-exploitation tool called VShell.

    Way back in February 2026, two other vulnerabilities in the same product (CVE-2025-49113 and CVE-2025-68461) were tagged as actively exploited by the U.S. Cybersecurity and Infrastructure Security Agency (CISA).

    actively Exploited Flaw Injection PreAuth Roundcube SQL wild
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Microsoft: Recent Windows updates cause desktop loading issues

    Hackers steal $351.6 million in Bitget crypto exchange hack

    WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV

    Roundcube Webmail Vulnerability in Attackers’ Crosshairs

    Cloudflare Fixes Flaw That Let One Container Read Another Customer’s Leftover Disk Data

    17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Did Milwaukee juvenile homicides increase 57% under David Crowley?

    September 25, 2026

    What Milwaukee can learn from Baltimore’s community policing plan

    September 25, 2026

    Can Michelle Bolsonaro Help Brazil’s Far Right Win Over Women Voters?

    September 25, 2026

    Trump made ‘final decision’ to give Ukraine Patriot licence, Zelensky says

    September 25, 2026
    Latest Posts

    Spain’s Pedro Sánchez is a progressive outlier in Europe – and over Ceuta, he is being made to pay for it | Eoghan Gilmartin

    August 6, 2026

    Putin Signs Law For Russia To Regulate Crypto Exchanges

    August 6, 2026

    Canadian pleads guilty to Snowflake cloud data-theft attacks

    August 6, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Did Milwaukee juvenile homicides increase 57% under David Crowley?

    September 25, 2026

    What Milwaukee can learn from Baltimore’s community policing plan

    September 25, 2026

    Can Michelle Bolsonaro Help Brazil’s Far Right Win Over Women Voters?

    September 25, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.