roundcube-webmail-attack

Roundcube Webmail, which is included in many hosting control panels, has an actively exploited vulnerability that can expose email account passwords and company messages.

Roundcube is the web interface that many small businesses use to check their email; it comes pre-installed in hosting control panels such as cPanel or Plesk. A vulnerability identified by the CVE-2026-48842 code allows an unauthenticated attacker to inject commands into the database through a component used for user searches. Through this vulnerability, an attacker can gain access to email account passwords and stored messages.

The problem is all the more serious because it is already being exploited in real-world attacks, and a fix is available in versions 1.6.16 and 1.7.1—yet many installations remain unpatched. Researchers at Shadowserver have identified over 500,000 Roundcube instances exposed on the internet.

For a small business, a compromised email account is no minor incident. From a compromised inbox, fake invoices are sent to customers, along with requests to change bank account information (IBAN) and requests to reset passwords for other services linked to the same email address. Essentially, the email account is the key that unlocks the rest of the business.

What you need to do:

  • Update Roundcube to version 1.6.16 or 1.7.1, which include the fix.
  • If your webmail is managed by your hosting provider, ask them directly if they have applied the fix.
  • Enable two-step verification for your email accounts.
  • Change your email account passwords if you were running an older, vulnerable version.
  • In a company without its own IT department, designate someone to monitor updates in the hosting control panel—the assumption that “the hosting takes care of itself” is exactly the gap that a maintenance service fills.

A timely update and two-step verification via email make the difference between a reported breach and a lost account.

Sources:

This article was generated with AI assistance.

Request a quote

← All news