logo

Critical XSS Vulnerability In Roundcube Let Attackers Execute Arbitrary Code

ID: b6512d4f-bf05-5bb9-a4c1-b5301b3d7755

STIX ID: report--b6512d4f-bf05-5bb9-a4c1-b5301b3d7755

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2024-08-09

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Roundcube webmail contains critical XSS vulnerabilities (CVE-2024-42009 — zero‑click; CVE-2024-42008 — single‑click) that have been exploited in the wild by the Winter Vivern APT to exfiltrate emails and steal credentials from government and military targets; administrators should urgently upgrade to patched versions (1.6.8 or 1.5.8) and affected users should change passwords and clear site data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.