Roundcube Email Flaw Is Being Exploited, So Patch Now, US Government Warns

A vulnerability in the Roundcube email server platform is being actively exploited, the US government warns, urging its agencies to patch and secure their instances as soon as possible.

In a security advisory, the Cybersecurity and Infrastructure Security Agency (CISA) said that a persistent cross-site scripting (XSS) bug is being actively exploited. The bug, tracked as CVE-2023-43770, is abused via custom links and plain text messages.

scroll to top