Mathew Potter
Security Analyst
The Canadian Centre for Cyber Security updated a May note and said the Roundcube hole is being used. BleepingComputer carried it this morning. CVE-2026-48842 is a pre-authentication SQL injection in the virtuser_query plugin, the piece that maps users to mailboxes from a database. No login. No click. Roundcube patched it in May: 1.6.16 and 1.7.1. Four months later, Ottawa is telling administrators to finish the job. If you cannot update today, they say disable or remove that plugin. That is the workaround. The update is the close.
A lot of small hosts and professional offices run Roundcube because it came with the cPanel or the mail appliance. virtuser_query is how some of those boxes look up who owns an address. The May advisory called the hole high complexity and still scored it 8.1. Successful use, in that write-up, is database commands and a path to data in Roundcube's own tables. We are not going to walk the query. The useful facts are the versions and the plugin name.
The Cyber Centre's original AV26-503 landed May 25. Monday's update is the sentence that matters: open-source reporting says it is exploited in the wild. That is not a new CVE. It is a May patch that shops filed under "later."
Roundcube sits behind a lot of @company.ca inboxes that never got a product name in the IT inventory. The site is WordPress. The panel is cPanel. The webmail is "the round login page." If that page is still on 1.6.15 or 1.7.0, you are on the May list with a September stamp. Pair that with yesterday's CalDAV-to-root on the same shared box and you have two ways a customer login, or no login at all, becomes the host.
A May webmail patch that Ottawa had to mention again in September is still a September job if you have not applied it. Forensic Five reviews the page people actually use to read mail, not only the firewall in front of it. From St. Albert, Alberta. Update Roundcube. Then go look at WordPress 7.1.2 and the TeamCity box, because those two are being used for worse than a mailbox.
Security Analyst
Mathew leads assessments and consulting at Forensic Five from St. Albert, Alberta. His background is Linux systems, networks, and application infrastructure.