2026-05-28HIGHexploitedCVE-2026-48842, Roundcube Webmail pre-authentication SQL injection in virtuser_query plugin (CVSS 8.1)
Roundcube Webmail HTML sanitisation bypass via SVG document permitting CSS injection; patched in 1.6.16 LTS / 1.7.1
cve · CVE-2026-48848
Coverage
1
first 2026-05-28 → last 2026-09-25
Latest activity
2026-09-25
CVE-2026-48842, Roundcube Webmail pre-authentication SQL injection in virtuser_query plugin (CVSS 8.1)
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, education, telco · regions: europe
Sources cited
5
5 hosts
Action items (1)
Do-now tasks recorded on the entries about CVE-2026-48848, newest first. Check the date before acting on an older one.
- Roundcube (upgrade to 1.6.16 LTS or 1.7.1 now; CVE-2026-48842 is confirmed under active exploitation. Where immediate patching is not possible, disable or remove the2026-05-28CVE-2026-48842 +3
virtuser_queryplugin entirely) it is opt-in and mainly used by hosting/ISP-style deployments. Reference: Canadian Centre for Cyber Security, 2026-09-21.
Defender insights
What each entry about CVE-2026-48848 tells a defender to do, newest first.
Triage
Story timeline
Hunting pivots
Affected products
ATT&CK techniques (1 across 1 tactic)
1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-05-28/cve-2026-48842-roundcube-webmail-pre-authentication-sql-inje · ATT&CK page ↗
Entries about Roundcube Webmail HTML sanitisation bypass via SVG document permitting CSS injection; patched in 1.6.16 LTS / 1.7.1 (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Roundcube Webmail×1
- Roundcube Webmail code injection via LDAP autovalues option; arbitrary PHP code evaluation when option is configured; patched in 1.6.16 LTS / 1.7.1×1
- Roundcube Webmail CSS sanitisation failure via SVG animate attributeName=style, info disclosure / SSRF in HTML email rendering; patched in 1.6.16 LTS / 1.7.1×1
- Roundcube Webmail pre-auth SQL injection in virtuser_query plugin via preg_replace backslash escape bypass; CVSS 8.1; patched in 1.6.16 LTS / 1.7.1×1
Where this entity is cited
Source distribution
- bleepingcomputer.com1 (20%)
- cyber.gc.ca1 (20%)
- heise.de1 (20%)
- roundcube.net1 (20%)
- security-hub.ncsc.admin.ch1 (20%)
External references
All cited sources (5)
- roundcube.netprimaryRoundcube Projecthttps://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/critical-roundcube-flaw-now-actively-exploited-in-code-injection-attacks/
- cyber.gc.caCanadian Centre for Cyber Securityhttps://www.cyber.gc.ca/en/alerts-advisories/roundcube-security-advisory-av26-503
- heise.deHeise Securityhttps://www.heise.de/news/Roundcube-Webmail-Instanzen-mit-Schadcode-attackierbar-11307545.html
- security-hub.ncsc.admin.chNCSC Switzerland post 12596https://security-hub.ncsc.admin.ch/#/posts/12596