A high-severity vulnerability in Roundcube Webmail, patched in May, is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security. The flaw allows code injection, giving attackers a way to run malicious code on affected systems. BleepingComputer reports that the warning marks a shift from theoretical risk to confirmed in-the-wild exploitation.
Roundcube is a widely used open-source webmail client, often deployed on servers that handle sensitive communications. Because the patch has been available for months, unpatched installations are now a clear target. The Canadian agency's alert suggests attackers have added this flaw to their active toolkit, making immediate action important for any organization still running a vulnerable version.
Administrators should confirm that the May security update has been applied to all Roundcube instances. If not, patching should be treated as urgent. Given that exploitation is already underway, organizations should also review logs for signs of code injection or unusual activity, as waiting to act could leave systems exposed to compromise.