OFFSEC · Offensive Security

The Roundcube fix shipped in May. Exploitation was confirmed in September

A pre-authentication SQL injection flaw in Roundcube Webmail was patched on 24 May 2026 and confirmed exploited on 21 September. Over half a million instances are exposed, most of them in estates that have no vulnerability management process at all, and every scoring input rated the flaw unlikely to be exploited.

What was fixed, and when

On 24 May 2026 the Roundcube project released versions 1.6.16 and 1.7.1, closing eight security issues [1]. One of them is described in the release announcement as a pre-authentication SQL injection in a plugin [1]. That issue is CVE-2026-48842: a pre-authentication SQL injection in the virtuser_query plugin, reachable through a preg_replace() backslash escape bypass, classified CWE-89 [2]. It affects Roundcube 1.6.x before 1.6.16 and 1.7.x before 1.7.1 [2].

The CVSS v3.1 score is 8.1, vector AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H [3]. Two elements of that vector matter more than the number. PR:N and UI:N mean no credentials and no user action. AC:H means the attack is not trivial to execute reliably, which is the part that kept the flaw quiet for four months and is also the part that stops mattering once someone has done the work.

The Roundcube release credits several external reporters across the eight issues, including Anand Jogawade, wooseokdotkim, skull, the Orange Cyberdefense Vulnerability Disclosure Team, Geame, valent1 and Glendaenri [1]. The announcement does not map individual reporters to individual issues, so no attribution of this specific finding to a named researcher is made here.

The exploitation signal

The Canadian Centre for Cyber Security issued advisory AV26-503 on 25 May 2026 and updated it on 21 September 2026. The updated advisory states that CVE-2026-48842 is being exploited in the wild [5]. Two independent accounts of that update describe the Cyber Centre's basis as reporting from the open-source community identifying ongoing exploitation [7] [8]. No vendor incident report, no named researcher and no indicator set has been published for this activity at the time of writing.

Shadowserver telemetry places more than 523,000 Roundcube instances on the internet [6]. That figure is the population, not the vulnerable subset, and nobody has published how many of those instances run an affected version with virtuser_query enabled. The absence of that breakdown is itself informative: this is not a population that is routinely inventoried.

Why the gap was four months, and why the last one was 48 hours

Roundcube has a recent precedent that runs in the opposite direction. CVE-2025-49113, an authenticated deserialisation flaw, was patched on 1 June 2025. Exploitation followed within 48 hours of the patch, after the fix was diffed and weaponised — the assessment of researcher Kirill Firsov, as reported at the time [9]. Shadowserver then counted over 1,200,000 Roundcube instances online with 84,925 still vulnerable as of 8 June 2025, the largest concentrations being 19,500 in the United States and 15,500 in India, followed by Germany, France, Canada and the United Kingdom [9] [10].

The same codebase, the same patch-diff opportunity, and a gap of two days rather than four months. The difference is not the severity of the flaw. It is attention: whether someone with the skill to build a reliable exploit chose to look at that commit in that week. Defenders who schedule remediation by predicted exploitation probability are betting on that choice, and they cannot observe it.

The predictive inputs were unhelpful in both directions here. Three vulnerability databases publish three different EPSS readings for CVE-2026-48842: 0.00076, or 0.076 per cent [3]; 0.764 per cent at the 51st percentile [2]; and 0.89 per cent at the 58th percentile [4]. These are snapshots from different dates rather than a contradiction, but the practical effect is the same — a flaw now confirmed exploited sat under one per cent in every reading. One of those databases also carries a recommended severity assessment of 'Low' for an issue scored 8.1 by CVSS [4]. An organisation that filters on either signal would not have patched this in May.

The population has no patch owner

Roundcube's exposure profile is different from an enterprise appliance. It is bundled with shared hosting control panels, which means a large part of the installed base belongs to small organisations that do not know they are running it, do not know which version, and have no process that would notice a May release note [6]. The 2025 distribution figures make the same point geographically: India held the second-largest vulnerable population, ahead of every European country counted [9]. This is the mail system for a substantial part of the small-business internet across Asia, and it is maintained by whoever the hosting provider happens to be.

That matters for the impact assessment. A pre-authentication SQL injection reaches the application database before any login occurs. Roundcube's database holds user records, address books, saved configuration and, depending on deployment, credential material used to bind to the mail backend. Where exploitation is suspected, the contents of that database are in scope, not merely the application binary.

Webmail is a collection target, not a convenience

Roundcube has been attacked for access to correspondence before. In October 2023, ESET's Matthieu Faou reported a zero-day cross-site scripting flaw, CVE-2023-5631, exploited by the group ESET tracks as Winter Vivern against European governmental entities and a think tank; the payload listed folders and exfiltrated whole messages to actor infrastructure, triggered simply by viewing the email [11]. That attribution is ESET's assessment, reported as such. ESET's stated reason for the exposure is worth keeping: a significant number of internet-facing applications are not regularly updated although they are known to contain vulnerabilities [11].

The value of a webmail server to an intelligence-motivated operator is direct. It is the correspondence itself, the address book that maps an organisation's relationships, and a credential store that often unlocks more than mail. The 2023 case required a user to open a message. This one requires nothing.

Actions

  • Upgrade to Roundcube 1.6.16 or 1.7.1 or later. Distribution packages carry their own version strings — on Debian 13 the fixed package is 1.6.16+dfsg-0+deb13u1 — so verify the package version, not the upstream release number [1] [4].
  • Where virtuser_query is not required by the deployment, disable the plugin. Published mitigation guidance names this as the interim control alongside restricting public access until the upgrade is complete [8].
  • Confirm the database account used by Roundcube is least-privilege. A pre-authentication injection inherits whatever that account can do [8].
  • Review web and database logs for anomalous pre-authentication request patterns and unexpected SQL activity, and for authentication events that do not correspond to a successful login [7] [8].
  • Where exploitation is suspected, treat the Roundcube database as exposed: rotate any credentials it holds, including mail backend binds, and assess stored user data as read rather than assuming integrity of the application was the only loss.
  • Inventory the shared-hosting and control-panel estate. If the organisation's mail is served by a provider's Roundcube instance, the remediation owner is the provider, and that needs to be asked in writing rather than assumed [6].

Domain note

Offensive security practice has a long-standing bias towards the newest disclosure. This case argues for the opposite discipline. The vulnerability was public, patched, scored, catalogued in three databases and assigned a sub-one-per-cent exploitation probability, and it remained unexploited for four months in a population of more than half a million internet-facing instances. Nothing about it changed in September except that someone decided to build the exploit. For a red team, that four-month window is the realistic operating environment. For a defender, it is the reason a remediation programme driven by predicted likelihood will keep being surprised by flaws it correctly deprioritised.

Sources

Every R3KONX article cites its primary material. 11 sources, in order of first citation. Links open the original publication.

  1. Security updates 1.6.16 and 1.7.1 Roundcube Webmail project · 2026-05-24
  2. GHSA-vc2v-cxrw-6g4p: Roundcube Webmail pre-authentication SQL injection (CVE-2026-48842) GitHub Advisory Database · 2026-05
  3. CVE-2026-48842 Tenable vulnerability database · 2026-05-25
  4. SQL Injection in roundcube u2014 SNYK-DEBIAN13-ROUNDCUBE-17037438 (CVE-2026-48842) Snyk Vulnerability Database · 2026
  5. Roundcube security advisory AV26-503 Canadian Centre for Cyber Security · 2026-09-21
  6. Hackers now exploit critical Roundcube flaw in code injection attacks BleepingComputer · 2026-09-24
  7. Roundcube Webmail SQL Injection Vulnerability Exploited in the Wild Cyber Security News · 2026-09-24
  8. Roundcube Webmail Flaw Lets Attackers Trigger SQL Injection Without Authentication GBHackers · 2026-09-24
  9. Over 84,000 Roundcube instances vulnerable to actively exploited flaw BleepingComputer · 2025-06-09
  10. Actively exploited Roundcube flaw has widespread coverage SC Media · 2025-06-10
  11. Winter Vivern exploits zero-day vulnerability in Roundcube Webmail servers ESET WeLiveSecurity (Matthieu Faou) · 2023-10-25

Researched and written by the R3KONX analysis desk from the cited primary material: the Roundcube project's own security release, the GitHub Advisory Database entry, the Canadian Centre for Cyber Security advisory, vulnerability database records from Tenable and Snyk, and prior ESET research. Methodological caveats: the CISA Known Exploited Vulnerabilities catalogue and the NVD record could not be retrieved from this environment, so KEV status is not asserted either way; MyCERT's advisory index also could not be retrieved, so no claim is made about Malaysian national advisory coverage; the exposure count is Shadowserver telemetry reported by a named publisher rather than read from Shadowserver directly; the three EPSS values quoted are snapshots taken on different dates. No exploitation detail is reproduced. Corrections to event@r3konx.asia.

R3KONX 2027

Work in this domain? So does the programme

4–6 May 2027, World Trade Centre Kuala Lumpur. Curated talks, hands-on training and The BattleGrid.