CISA: Roundcube email server bug now exploited in attacks
ID: 1e7e491e-e99a-5eb8-85f6-a6db0007447a
STIX ID: report--1e7e491e-e99a-5eb8-85f6-a6db0007447a
Feed Name: Bleeping Computer
CISA warns that a persistent cross-site scripting vulnerability in Roundcube (CVE-2023-43770) is being actively exploited and has been added to the Known Exploited Vulnerabilities catalog; federal agencies were ordered to patch affected Roundcube installations promptly. The report notes the affected Roundcube versions, that Shodan shows a large number of internet-exposed Roundcube servers, and references earlier Roundcube XSS exploits (CVE-2023-5631, CVE-2020-35730) used by Russian APTs such as Winter Vivern (TA473) and APT28 to steal emails from government and think-tank accounts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
