Patch now! Roundcube mail servers are being actively exploited
ID: 68769d39-3a07-5fab-b6fe-5f9db8989e9f
STIX ID: report--68769d39-3a07-5fab-b6fe-5f9db8989e9f
Feed Name: Malwarebytes Blog
CISA warns that Roundcube Webmail has a persistent XSS vulnerability (CVE-2023-43770) actively exploited in the wild; affected versions (pre-1.4.14, pre-1.5.4, pre-1.6.3) should be updated to patched releases (1.6.3 and later). The agency added the flaw to its Known Exploited Vulnerabilities Catalog and mandates remediation for federal agencies by March 4, 2024; roughly 132,000 Roundcube servers are internet-accessible, increasing potential impact as attackers can store and serve malicious payloads via email.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
