CVE-2023-43770Active Exploitation(debian / debian_linux)

MEDIUMCVSS 6.1 · MEDIUMCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for debian debian_linux systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_replacer.php behavior.

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-03-04. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-79

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • debian_linux
  • webmail

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-10); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
debian_linuxwebmail

1 version affected across 2 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-10: 1Mentions · 2026-07-24: 1Active Exploitation · 2026-04-10: 104-1007-24
Signal classification2 categories
Active Exploitation
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-101
Active Exploitation1
2026-07-241
Disclosure1
Full discourse2 posts
  • blackorbird@blackorbird
    Disclosure

    TA488(Void Blizzard、Laundry Bear) Targets Zimbra Mailservers with Half-Click Exploits https://www.proofpoint.com/us/blog/threat-insight/ta488-targets-zimbra-mailservers-half-click-exploits Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days from TA458 CVE-2025-27915: Zimbra (zero-day) CVE-2025-3929: mDaemon (zero-day) CVE-2023-43770: Roundcube (n-day) CVE-2024-42009: Roundcube (n-day) CVE-2026- 8496: SOGo (zero-day) https://www.proofpoint.com/us/blog/threat-insight/ta458-roundpress-exploits

    Post summary

    The text announces that threat actors TA488 and TA458 have identified multiple zero-day and other zero-day‑like vulnerabilities in webmail systems such as Zimbra, mDaemon, Roundcube, and SOGo, with a reference to a Proofpoint blog for additional details.

    0813299.1K
    43.8K followersView on X
  • thaddeus e. grugq@thegrugq
    Active Exploitation

    In Ukraine where 12 years of intense Russian hacking should have created a barren hardened wasteland with no vulnerable systems… CERT-UA reported CVE-2023-43770 (Roundcube) exploited heavily in 2024 and 2025.

    Post summary

    CERT-UA reports CVE-2023-43770 in Roundcube has been heavily exploited in Ukraine during 2024–2025, indicating ongoing real‑world attacks.

    2101831.9K
    127.9K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSdebiandebian_linux10.0--
Approundcubewebmail---

Explore more