Attackers are actively exploiting a vulnerability in Roundcube Webmail that allows pre-authentication SQL injection. The flaw is tracked as CVE-2026-48842 and is associated with the virtuser_query plugin. SecurityWeek and The Hacker News both report that the issue can be exploited without authentication and is being targeted in the wild.
CVE-2026-48842 affects specific Roundcube versions prior to security fixes. The Hacker News states that Roundcube 1.6.x versions before 1.6.16 and 1.7.x versions before 1.7.1 are impacted, citing a warning from the Canadian Centre for Cyber Security. The Hacker News also provides the vulnerability’s severity, listing a CVSS score of 8.1. SecurityWeek focuses on the exploitation risk and notes the issue is an SQL injection.
Across the reports, the main differences are emphasis: SecurityWeek highlights that attackers are pursuing the bug, while The Hacker News stresses the official guidance and version ranges, tying it directly to an ongoing campaign and the need to patch promptly.