Our takeCCC S reports active exploitation of CVE-2026-48842 in Roundcube Webmail. Update to 1.6.16 or 1.7.1 immediately if you run it yourself.Cyber Resilience desk
Sources (1)
- cccs · cccs
What this means for you — Security leader:Roundcube Webmail versions prior to 1.6.16 and 1.7.1 contain CVE-2026-48842, which is under active exploitation. Update immediately to 1.6.16 or 1.7.1.
What this means for you — Lean IT orgs:If you run your own Roundcube webmail server, update it right away to version 1.6.16 or 1.7.1. This flaw is already being exploited in the wild.
What this means for you — MSP:Audit all client environments running self-hosted Roundcube Webmail and update any instances below 1.6.16 or 1.7.1 on an emergency basis; this CVE is under active exploitation.
What this means for you — Researcher:Roundcube published fixes for CVE-2026-48842 in versions prior to 1.6.16 and 1.7.1. CCCS confirms active exploitation in the wild.