CVE-2023-2868Exploit(barracuda / email_security_gateway_300)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch barracuda email_security_gateway_300 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.001-9.2.0.006. The vulnerability arises out of a failure to comprehensively sanitize the processing of .tar file (tape archives). The vulnerability stems from incomplete input validation of a user-supplied .tar file as it pertains to the names of the files contained within the archive. As a consequence, a remote attacker can specifically format these file names in a particular manner that will result in remotely executing a system command through Perl's qx operator with the privileges of the Email Security Gateway product. This issue was fixed as part of BNSF-36456 patch. This patch was automatically applied to all customer appliances.

8.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2023-06-16. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-20CWE-77

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • email_security_gateway_300
  • email_security_gateway_300_firmware
  • email_security_gateway_400
  • email_security_gateway_400_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 4 mentions across 4 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Peaked 3d ago at 1 mentions (2026-02-19); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
email_security_gateway_300email_security_gateway_300_firmwareemail_security_gateway_400email_security_gateway_400_firmwareemail_security_gateway_600email_security_gateway_600_firmwareemail_security_gateway_800email_security_gateway_800_firmwareemail_security_gateway_900email_security_gateway_900_firmware

1 version affected across 10 products

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-02-19: 1Mentions · 2026-03-27: 1Mentions · 2026-03-28: 1Mentions · 2026-06-24: 1PoC Mentioned / Linked · 2026-03-28: 1Exploit Tool / Code · 2026-03-27: 1Exploit Tool / Code · 2026-03-28: 1Active Exploitation · 2026-02-19: 1Patch / Workaround · 2026-06-24: 1Technical Details · 2026-03-27: 1Technical Details · 2026-03-28: 102-1903-2703-2806-24
Signal classification3 categories
Exploit
250.0%
Active Exploitation
125.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-191
Active Exploitation1
2026-03-271
Exploit1
2026-03-281
Exploit1
2026-06-241
Patch1
Full discourse4 posts
  • Metasploit Project@metasploit
    Exploit

    The latest #Metasploit Wrapup is here! 🎉 This week brings enhanced SMB NTLM relaying for better client compatibility (including smbclient), plus new modules for RCE in Eclipse Che (CVE-2025-12548), Barracuda ESG command injection (CVE-2023-2868), and an ESC/POS printer injector. Check it out at https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-03-27-2026/

    Post summary

    Rapid7 announced new Metasploit modules that enable RCE in Eclipse Che, command injection in Barracuda ESG, and an ESC/POS printer exploit, expanding toolsets for attackers but with no indication of current active use.

    01102864.3K
    252.8K followersView on X
  • DFIR Radar@DFIR_Radar
    Exploit

    Metasploit adds 3 new exploit modules including CVE-2026-23767 (ESC/POS printer RCE), CVE-2025-12548 (Eclipse Che unauthenticated RCE), and CVE-2023-2868 (Barracuda ESG command injection). Enhanced NTLM relay compatibility with Linux smbclient. #DFIR_Radar https://t.co/kTThThSAHp

    Post summary

    Metasploit has released three new modules for CVE-2026-23767, CVE-2025-12548, and CVE-2023-2868, providing functional exploitation code for these vulnerabilities. The post does not mention active exploitation or any available patches.

    10010439
    1.2K followersView on X
  • PatchDayAlert@patchdayalert
    Patch

    Barracuda pushed a patch for CVE-2023-2868 in May 2023. It worked. Customers still had to replace the entire appliance anyway. Here's why the patch wasn't enough. https://patchdayalert.com/blog/barracuda-esg-cve-2023-2868-replace-not-patch/?utm_source=x&utm_medium=social&utm_campaign=blog-tease&utm_content=barracuda-esg-cve-2023-2868-replace-not-patch

    Post summary

    Barracuda released a patch for CVE‑2023‑2868 that proved insufficient, leading customers to replace their appliances.

    0100066
    75 followersView on X
  • ThreatCluster@threatcluster
    Active Exploitation

    Early 2026 reports show rising cloud compromises via misconfigured services and CVE-2023-3519, CVE-2023-2868, CVE-2021-43798 exploitation, expanding victim impact across sectors. #CloudSecurity https://threatcluster.io/cluster/cloud-compromise-driven-by-security-tool-misuse-and-vulnerab-c2addaf1

    Post summary

    The post reports that cloud compromises are increasing, driven by misconfigured services and active exploitation of CVE-2023-3519, CVE-2023-2868, and CVE-2021-43798 across multiple sectors.

    0000064
    71 followersView on X
CPE platform detail10 entries

10 of 10 entries

PartVendorProductVersionTarget SWTarget HW
HWbarracudaemail_security_gateway_300---
OSbarracudaemail_security_gateway_300_firmware---
HWbarracudaemail_security_gateway_400---
OSbarracudaemail_security_gateway_400_firmware---
HWbarracudaemail_security_gateway_600---
OSbarracudaemail_security_gateway_600_firmware---
HWbarracudaemail_security_gateway_800---
OSbarracudaemail_security_gateway_800_firmware---
HWbarracudaemail_security_gateway_900---
OSbarracudaemail_security_gateway_900_firmware---

Explore more