Roundcube email flaw is being exploited, so patch now, US government warns

A vulnerability in the Roundcube email server platform is being actively exploited, the US government has warned, urging its agencies to apply the patch and secure their agencies as early as possible.

In a security advisory, the Cybersecurity and Infrastructure Security Agency (CISA) said that a persistent cross-site scripting (XSS) bug is being actively exploited in the wild. The bug, tracked as CVE-2023-43770, is exploited via customized plain text messages and links.