logo

Alert: CISA Warns of Active 'Roundcube' Email Attacks - Patch Now

ID: e331a045-6598-5080-adbf-f3b7734a6fbf

STIX ID: report--e331a045-6598-5080-adbf-f3b7734a6fbf

Feed Name: The Hacker News

Threat Score
60/100

Date Published: 2024-02-13

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

CISA added CVE-2023-43770 (persistent XSS in Roundcube Webmail, CVSS 6.1) to its Known Exploited Vulnerabilities catalog after evidence of active exploitation; affected Roundcube releases prior to 1.4.14, 1.5.4 and 1.6.3 should be updated to the vendor-fixed 1.6.3 release, and U.S. federal civilian agencies have been mandated to apply vendor fixes by March 4, 2024.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.