"CISA: Roundcube Email Server Bug Now Exploited in Attacks"
"CISA: Roundcube Email Server Bug Now Exploited in Attacks"
According to the Cybersecurity and Infrastructure Security Agency (CISA), a Roundcube email server vulnerability patched in September 2023 is being actively exploited in Cross-Site Scripting (XSS) attacks. The security vulnerability, tracked CVE-2023-43770, is a persistent XSS flaw that enables attackers to gain access to restricted information. CISA has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, warning that these security flaws pose significant risks to the federal enterprise.