PT Expert Security Center

Fake attachment. Roundcube mail server attacks exploit CVE-2024-37383 vulnerability

Fake attachment. Roundcube mail server attacks exploit CVE-2024-37383 vulnerability

Roundcube Webmail is an open-source email client written in PHP. Its extensive functionality and the convenient access it gives users to email accounts via a browser—without the need for full-fledged email clients—have made it popular among commercial and government organizations worldwide. However, this popularity also makes it an attractive target for cybercriminals who quickly adapt exploits once they become publicly known, aiming to steal credentials and corporate email communications.