{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3obarracudaemail_security_gateway_300_firmware/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:barracuda:email_security_gateway:*:*:*:*:*:*:*:*","cpe:2.3:o:barracuda:email_security_gateway_300_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:barracuda:email_security_gateway_400_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:barracuda:email_security_gateway_600_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:barracuda:email_security_gateway_800_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:barracuda:email_security_gateway_900_firmware:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.4,"id":"CVE-2023-2868"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Email Security Gateway"],"_cs_severities":["high"],"_cs_tags":["vulnerability","rce","network-security"],"_cs_type":"advisory","_cs_vendors":["Barracuda Networks"],"content_html":"\u003cp\u003eBarracuda Networks has identified a critical vulnerability in the Email Security Gateway that facilitates remote code execution (RCE). The flaw, tracked as CVE-2023-2868, arises from improper input validation when the appliance processes incoming email attachments. Attackers can leverage this vulnerability to execute arbitrary code on the target appliance by sending specially crafted email attachments. Given the position of these appliances at the network perimeter, successful exploitation grants an attacker full control over the gateway, enabling potential interception of email traffic, credential harvesting, or lateral movement into the internal network. Defenders should prioritize patching affected appliances immediately to mitigate the risk of exploitation.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2023-2868 results in unauthenticated remote code execution on the Barracuda Email Security Gateway. This allows for total system compromise, including the potential for data exfiltration of sensitive communications and unauthorized access to protected internal resources within the enterprise network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize patching all internet-facing Barracuda Email Security Gateway appliances to the latest vendor-supplied version to remediate CVE-2023-2868.\u003c/p\u003e\n","date_modified":"2026-09-22T13:56:48Z","date_published":"2026-09-22T13:56:48Z","id":"https://feed.craftedsignal.io/briefs/2026-09-barracuda-rce/","summary":"A critical remote code execution vulnerability in Barracuda Email Security Gateway caused by improper input validation of email attachments allows attackers to execute arbitrary code.","title":"Remote Code Execution in Barracuda Email Security Gateway","url":"https://feed.craftedsignal.io/briefs/2026-09-barracuda-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:o:barracuda:email_security_gateway_300_firmware:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}