Skip to content
Threat Feed
high advisory

Remote Code Execution in Barracuda Email Security Gateway

A critical remote code execution vulnerability in Barracuda Email Security Gateway caused by improper input validation of email attachments allows attackers to execute arbitrary code.

CVE search metadata

CVE search record: CVE-2023-2868. Severity: critical. CVSS: 9.4. EPSS: 87.69%. KEV: no. Product: Email Security Gateway. Brief: Remote Code Execution in Barracuda Email Security Gateway. Brief link: https://feed.craftedsignal.io/briefs/2026-09-barracuda-rce/

Barracuda Networks has identified a critical vulnerability in the Email Security Gateway that facilitates remote code execution (RCE). The flaw, tracked as CVE-2023-2868, arises from improper input validation when the appliance processes incoming email attachments. Attackers can leverage this vulnerability to execute arbitrary code on the target appliance by sending specially crafted email attachments. Given the position of these appliances at the network perimeter, successful exploitation grants an attacker full control over the gateway, enabling potential interception of email traffic, credential harvesting, or lateral movement into the internal network. Defenders should prioritize patching affected appliances immediately to mitigate the risk of exploitation.

Impact

Successful exploitation of CVE-2023-2868 results in unauthenticated remote code execution on the Barracuda Email Security Gateway. This allows for total system compromise, including the potential for data exfiltration of sensitive communications and unauthorized access to protected internal resources within the enterprise network.

Recommendation

Prioritize patching all internet-facing Barracuda Email Security Gateway appliances to the latest vendor-supplied version to remediate CVE-2023-2868.


Immediate actions

Patch Barracuda Email Security Gateway to the latest version to address CVE-2023-2868.

IT Operations 24h

Mitigations

Upgrade Barracuda Email Security Gateway to the vendor-recommended patched version.

immediate IT Operations

CVE-2023-2868