• News/
  • https://www.bleepingcomputer.com/news/security/cisa-roundcube-email-server-bug-now-exploited-in-attacks/

CISA: Roundcube email server bug now exploited in attacks

BleepingComputer
·
Sergiu Gatlan
·
Published Feb 12, 2024
·
Updated

CISA warns that a Roundcube email server vulnerability patched in September is now actively exploited in cross-site scripting (XSS) attacks. The security flaw (CVE-2023-43770) is a persistent cross-site scripting (XSS) bug that lets attackers access restricted information via plain/text messages maliciously crafted links in low-complexity attacks requiring user interaction. The vulnerability impacts Roundcube email servers running versions newer than 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3. "We strongly recommend to update all productive installations of Roundcube 1.6.x with this new version," the Roundcube security team said when it released CVE-2023-43770 security updates five months ago. While it didn't provide any details on the attacks, CISA added the vulnerability to its Known Exploited Vulnerabilities Catalog, cautioning that such security flaws are "frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise." CISA also ordered U.S. Federal Civilian Executive Branch (FCEB) agencies to secure Roundcube webmail servers against this security bug within three weeks, by March 4, as mandated by a binding operational directive (BOD 22-01) issued in November 2021. Although the primary focus of the KEV catalog is to alert federal agencies about vulnerabilities that need to be patched as soon as possible, private organizations worldwide are also highly advised to prioritize addressing this flaw. Shodan is currently trackin...

Read full article

Affected Software

3 affected components
Roundcube email server=1.4.14
Roundcube email server=1.5.x before 1.5.4
Roundcube email server=1.6.x before 1.6.3
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the exploitation of a vulnerability in the Roundcube email server, specifically a persistent cross-site scripting (XSS) bug.

2

What security implications are discussed?

The article highlights that the CVE-2023-43770 vulnerability is being actively exploited by attackers, posing risks to user data and email security.

3

What versions of Roundcube email server are affected?

The affected versions include Roundcube email server 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3.

4

What type of attack is being utilized due to this vulnerability?

The vulnerability allows attackers to execute persistent cross-site scripting (XSS) attacks.

5

What should administrators do in response to this security alert?

Administrators are advised to update their Roundcube email server to the latest versions to mitigate this vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203