logo

CISA: Roundcube email server bug now exploited in attacks

ID: 1e7e491e-e99a-5eb8-85f6-a6db0007447a

STIX ID: report--1e7e491e-e99a-5eb8-85f6-a6db0007447a

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-02-12

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

CISA warns that a persistent cross-site scripting vulnerability in Roundcube (CVE-2023-43770) is being actively exploited and has been added to the Known Exploited Vulnerabilities catalog; federal agencies were ordered to patch affected Roundcube installations promptly. The report notes the affected Roundcube versions, that Shodan shows a large number of internet-exposed Roundcube servers, and references earlier Roundcube XSS exploits (CVE-2023-5631, CVE-2020-35730) used by Russian APTs such as Winter Vivern (TA473) and APT28 to steal emails from government and think-tank accounts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.