Roundcube’s SQL injection flaw is now actively exploited, four months after the patch
Patched in May 2026, the pre-authentication SQL injection CVE-2026-48842 in Roundcube Webmail’s virtuser_query plugin is now being exploited in the wild, according to the Canadian Centre for Cyber Security. Administrators should upgrade to 1.6.16 or 1.7.1, or disable the virtuser_query plugin without waiting.