A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.001-9.2.0.006. The vulnerability arises out of a failure to comprehensively sanitize the processing of .tar file (tape archives). The vulnerability stems from incomplete input validation of a user-supplied .tar file as it pertains to the names of the files contained within the archive. As a consequence, a remote attacker can specifically format these file names in a particular manner that will result in remotely executing a system command through Perl's qx operator with the privileges of the Email Security Gateway product. This issue was fixed as part of BNSF-36456 patch. This patch was automatically applied to all customer appliances.
Conclusion & alert: CVE-2023-2868 is rated Critical Active Threat (98.8/100): CVSS Critical severity, with high exploitation likelihood (EPSS 89.21%, 100th percentile). Core evidence: CISA KEV confirms active exploitation (added 2023-05-26) affecting Barracuda Networks / Email Security Gateway (ESG) Appliance. a weakness (CWE-20) Unauthenticated remote administrative access may be possible. EPSS rose +1.40% over the last day, indicating growing attacker interest. Mandatory action: The CISA remediation deadline has passed—treat as an emergency patch priority.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
: Barracuda Networks ESG Appliance Improper Input Validation Vulnerability · CISA KEV detail
: 2023-05-26
: 2023-06-16
: Apply updates per vendor instructions.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-27 | 87.81% | 89.21% | +1.40% |
| 2 | 2026-05-25 | 89.98% | 87.81% | -2.16% |
| 3 | 2026-05-23 | — | 89.98% | — |
Full EPSS history (64 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.4 | 3.1 | CRITICAL |
|
3.9 | 5.5 | [email protected] |
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| barracuda | email_security_gateway_300_firmware | >= 5.1.3.001, <= 9.2.0.006 | cpe:2.3:o:barracuda:email_security_gateway_300_firmware:*:*:*:*:*:*:*:* |
| barracuda | email_security_gateway_400_firmware | >= 5.1.3.001, <= 9.2.0.006 | cpe:2.3:o:barracuda:email_security_gateway_400_firmware:*:*:*:*:*:*:*:* |
| barracuda | email_security_gateway_600_firmware | >= 5.1.3.001, <= 9.2.0.006 | cpe:2.3:o:barracuda:email_security_gateway_600_firmware:*:*:*:*:*:*:*:* |
| barracuda | email_security_gateway_800_firmware | >= 5.1.3.001, <= 9.2.0.006 | cpe:2.3:o:barracuda:email_security_gateway_800_firmware:*:*:*:*:*:*:*:* |
| barracuda | email_security_gateway_900_firmware | >= 5.1.3.001, <= 9.2.0.006 | cpe:2.3:o:barracuda:email_security_gateway_900_firmware:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://status.barracuda.com/incidents/34kx82j5n4q9 | Vendor Advisory |
| https://www.barracuda.com/company/legal/esg-vulnerability | Mitigation Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-2868 | US Government Resource |