500,000+ Roundcube Servers Exposed as CVE-2026-48842 SQL Injection Bypasses preg_replace Escaping
Active exploitation of Roundcube CVE-2026-48842 confirms repeated targeting of open-source webmail lacking update enforcement. Evidence shows unauthenticated SQLi via escaping bypass; 500k+ exposed servers face ongoing risk. Patching velocity and attribution gaps remain the critical operational shortfalls.
The vulnerability allows crafted backslash sequences to defeat the plugin’s regex escaping, concatenating quote characters directly into SQL statements sent to the database. SentinelOne’s technical breakdown shows the bypass succeeds without authentication, enabling extraction of mailboxes, address books, and authentication mappings. Over 500,000 Roundcube servers remain reachable per Shadowserver Foundation scans; the fraction still on versions before 1.6.16 and 1.7.1 is unknown but likely substantial given slow self-hosted patching cycles.
This marks the fourth Roundcube flaw in two years (CVE-2025-68461, CVE-2025-49113, CVE-2024-37383) to see rapid post-disclosure use. Procurement records and job postings from government and enterprise mail operators continue to list Roundcube deployments without mandatory update SLAs, creating persistent exposure windows that commercial webmail vendors largely closed years ago.
Official statements note “open-source reporting” of exploitation but withhold IOCs or actor fingerprints. Technical evidence shows only the SQLi vector and data-access primitives; attribution to any specific group remains unconfirmed by independent telemetry. The pattern indicates opportunistic scanning of exposed webmail rather than targeted campaigns requiring prior access.
Unpatched instances will continue receiving automated probes. Operators should prioritize version checks against 1.6.16/1.7.1 and monitor database logs for anomalous virtuser_query queries; failure to do so leaves identity and message stores directly reachable.
Shadowserver: at least 15% of currently exposed Roundcube instances will remain on vulnerable versions 90 days after the May 2025 patches.
Sources (3)
- [1]SecurityWeek Roundcube Report(https://www.securityweek.com/roundcube-webmail-vulnerability-in-attackers-crosshairs/)
- [2]Shadowserver Foundation Exposure Data(https://www.shadowserver.org/)
- [3]SentinelOne Technical Analysis(https://www.sentinelone.com/blog/)