Remote Code Execution in Barracuda Email Security Gateway
A critical remote code execution vulnerability in Barracuda Email Security Gateway caused by improper input validation of email attachments allows attackers to execute arbitrary code.
CVE search metadata
CVE search record: CVE-2023-2868. Severity: critical. CVSS: 9.4. EPSS: 87.69%. KEV: no. Product: Email Security Gateway. Brief: Remote Code Execution in Barracuda Email Security Gateway. Brief link: https://feed.craftedsignal.io/briefs/2026-09-barracuda-rce/
Barracuda Networks has identified a critical vulnerability in the Email Security Gateway that facilitates remote code execution (RCE). The flaw, tracked as CVE-2023-2868, arises from improper input validation when the appliance processes incoming email attachments. Attackers can leverage this vulnerability to execute arbitrary code on the target appliance by sending specially crafted email attachments. Given the position of these appliances at the network perimeter, successful exploitation grants an attacker full control over the gateway, enabling potential interception of email traffic, credential harvesting, or lateral movement into the internal network. Defenders should prioritize patching affected appliances immediately to mitigate the risk of exploitation.
Impact
Successful exploitation of CVE-2023-2868 results in unauthenticated remote code execution on the Barracuda Email Security Gateway. This allows for total system compromise, including the potential for data exfiltration of sensitive communications and unauthorized access to protected internal resources within the enterprise network.
Recommendation
Prioritize patching all internet-facing Barracuda Email Security Gateway appliances to the latest vendor-supplied version to remediate CVE-2023-2868.
Immediate actions
Patch Barracuda Email Security Gateway to the latest version to address CVE-2023-2868.
Mitigations
Upgrade Barracuda Email Security Gateway to the vendor-recommended patched version.
CVE-2023-2868