# CISA: Roundcube email server bug now exploited in attacks

**<mark>February 12, 2024</mark>**

---

CISA warns that a **<mark> Roundcube</mark>** email server vulnerability patched in September is now actively exploited in **<mark> cross-site scripting (XSS) attacks.</mark>**

The security flaw (**<mark>CVE-2023-43770</mark>**) is a **<mark>persistent cross-site scripting (XSS) </mark>** bug that lets attackers access restricted information via plain/text messages maliciously crafted links in low-complexity attacks requiring user interaction.

The vulnerability impacts **<mark>Roundcube email servers running versions newer than 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3.</mark>**

"We strongly recommend to update all productive installations of Roundcube 1.6.x with this new version," the Roundcube security team said when **<mark>it released CVE-2023-43770 security updates </mark>** five months ago.

While it didn't provide any details on the attacks, CISA added the vulnerability to its Known Exploited Vulnerabilities Catalog, cautioning that such security flaws are "**<mark>frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise</mark>**."

CISA also ordered U.S. Federal Civilian Executive Branch (FCEB) agencies to secure Roundcube webmail servers against this security bug within three weeks, by March 4, as **<mark>mandated by a binding operational directive (BOD 22-01) issued </mark>** in November 2021.

Although the primary focus of the KEV catalog is to alert federal agencies about vulnerabilities that need to be patched as soon as possible, **<mark>private organizations worldwide are also highly advised to prioritize addressing this flaw</mark>**.

Another Roundcube flaw, a stored cross-site scripting (XSS) vulnerability tracked as **<mark>CVE-2023-5631</mark>**, was targeted as a zero-day by the **<mark>Winter Vivern (aka TA473) </mark>** Russian hacking group since at least October 11.

The attackers used HTML email messages containing carefully **<mark>crafted malicious SVG documents designed to inject arbitrary JavaScript code </mark>** remotely.

The JavaScript payload dropped in the October attacks allowed the **<mark>Russian hackers to steal emails from compromised Roundcube webmail servers </mark>** belonging to government entities and think tanks in Europe.

Winter Vivern operators also **<mark>exploited the CVE-2020-35730 Roundcube XSS vulnerability </mark>** between August and September 2023.

The same bug was used by the **<mark> Russian APT28 cyber-espionage group</mark>**, part of Russia's General Staff Main Intelligence Directorate (GRU), to breach Roundcube email servers belonging to the Ukrainian government.

Winter Vivern hackers also **<mark>exploited the Zimbra CVE-2022-27926 XSS vulnerability in early-2023 to target NATO countries</mark>** and steal emails belonging to NATO governments, officials, and military personnel.
