Patch first › Barracuda Networks
CVE-2023-2868
Barracuda Networks Email Security Gateway (ESG) · Email
Barracuda Networks ESG Appliance Improper Input Validation Vulnerability
At a glance
Exploited. Added to CISA’s catalog of exploited vulnerabilities on May 26, 2023.
Affected product: Barracuda Networks Email Security Gateway (ESG) (category Email, indicative classification). Name in CISA’s catalog: Barracuda Networks Email Security Gateway (ESG) Appliance.
What should I do?
Apply the security update from Barracuda Networks.
Deadline set by CISA for US federal agencies: 21 days (due June 16, 2023). It only binds those agencies, but it is a useful measure of urgency.
- The vendor’s specific advisory is listed in the NVD references: CVE-2023-2868 on the NVD website.
Original text of the required action (CISA)
Apply updates per vendor instructions.
Timeline
- Vulnerability published Publication date (NVD)
- Exploitation confirmed Added to CISA’s KEV catalog
- CISA deadline Remediation deadline set for US federal agencies
The facts, with their sources
- Exploitation confirmed
- Yes, on May 26, 2023 Date added to the catalog of exploited vulnerabilities. Exploitation itself may have started earlier. Source: KEV catalog, collected September 29, 2026 at 14:57 UTC
- Ransomware
- No known use to date That does not guarantee it is not being used: the information is not public. Source: KEV catalog, collected September 29, 2026 at 14:57 UTC
- Hunt for compromise
- Not requested by CISA Source: KEV catalog, collected September 29, 2026 at 14:57 UTC
- CISA required action
- Apply the security update from Barracuda Networks. Rewritten by this site from CISA’s original text. Source: KEV catalog, collected September 29, 2026 at 14:57 UTC
- CISA deadline
- June 16, 2023, 21 days Set for US federal agencies: a measure of urgency, not an obligation elsewhere. Source: KEV catalog, collected September 29, 2026 at 14:57 UTC
- Vulnerability published
- May 24, 2023 Source: National Vulnerability Database (NVD), collected September 29, 2026 at 15:00 UTC
- Product according to CISA
- Barracuda Networks Email Security Gateway (ESG) Appliance Filed by this site under “Email” (indicative classification). Source: KEV catalog, collected September 29, 2026 at 14:57 UTC
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Technical detail of the score: attack vector, complexity, impact. Source: National Vulnerability Database (NVD), collected September 29, 2026 at 15:00 UTC
Severity and activity
FIRST’s EPSS model. Since exploitation is already confirmed, this figure is mostly useful to compare activity. Collected Sep 29, 2026.
Description
A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.001-9.2.0.006. The vulnerability arises out of a failure to comprehensively sanitize the processing of .tar file (tape archives). The vulnerability stems from incomplete input validation of a user-supplied .tar file as it pertains to the names of the files contained within the archive. As a consequence, a remote attacker can specifically format these file names in a particular manner that will result in remotely executing a system command through Perl's qx operator with the privileges of the Email Security Gateway product. This issue was fixed as part of BNSF-36456 patch. This patch was automatically applied to all customer appliances.
Official description from the NVD, collected Sep 29, 2026. CVE® description © The MITRE Corporation.
Barracuda Email Security Gateway (ESG) appliance contains an improper input validation vulnerability of a user-supplied .tar file, leading to remote command injection.
Summary from CISA (KEV catalog).
CERT-FR advisories
No advisory among the latest CERT-FR publications this site follows. That does not mean there are none.
Information reused under the Open Licence 2.0 (Etalab); the date of last update is shown for each advisory. This site is neither affiliated with nor endorsed by ANSSI.
Sources for this page
- CISA KEV catalog: exploitation, date added, required action, deadline, ransomware.
- NVD (NIST): CVSS severity, publication date, description, vendor references.
- EPSS (FIRST): probability of exploitation.
- CERT-FR: advisories and alerts (in French).
- Brand and category: indicative classification by this site (method).