Barracuda develops a focused portfolio of remote-management and email-security appliances that serve as critical choke points for inbound communications and system administration, concentrating its vulnerability exposure in gateway and firmware layers where input handling and command execution present persistent risk. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, with a moderate tendency toward confirmed in-the-wild exploitation, reflecting the high-value targets these appliances represent and the blast radius of flaws in security infrastructure. The recurring weakness classes—cross-site scripting, OS command injection, path traversal, and untrusted deserialization—are endemic to web-facing security gateways and underscore the tension between filtering rigor and parsing complexity. Defenders should treat this vendor's advisories with high urgency and prioritize patching internet-exposed appliances; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Barracuda over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-2868CRITICAL A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.001-9.2.0.006. The vulnerabili | May 24, 2023 | 9.8 | 97 | YES | YES |
CVE-2023-7102CRITICAL Use of a Third Party library produced a vulnerability in Barracuda Networks Inc. Barracuda ESG Appliance which allowed Parameter Injection.This issue affected Barracuda ESG Applian | Dec 24, 2023 | 9.8 | 67 | NO | YES |
CVE-2025-34392CRITICAL Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not verify the URL defined in an attacker-controlled WSDL that is later loaded by | Dec 10, 2025 | 9.8 | 45 | NO | NO |
CVE-2017-6320HIGH A remote command injection vulnerability exists in the Barracuda Load Balancer product line (confirmed on v5.4.0.004 (2015-11-26) and v6.0.1.006 (2016-08-19); fixed in 6.1.0.003 (2 | Jul 18, 2017 | 8.8 | 44 | NO | YES |
CVE-2014-2595CRITICAL Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a permanent authentication token obtained from a query string. | Feb 12, 2020 | 9.8 | 43 | NO | YES |
CVE-2025-34394CRITICAL Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, exposes a .NET Remoting service that is insufficiently protected against deserializatio | Dec 10, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-34393CRITICAL Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not correctly verify the name of an attacker-controlled WSDL service, leading to i | Dec 10, 2025 | 9.8 | 29 | NO | NO |
CVE-2023-26213HIGH On Barracuda CloudGen WAN Private Edge Gateway devices before 8 webui-sdwan-1089-8.3.1-174141891, an OS command injection vulnerability exists in /ajax/update_certificate - a craft | Mar 3, 2023 | 7.2 | 26 | NO | NO |
CVE-2025-34395HIGH Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, exposes a .NET Remoting service in which an unauthenticated attacker can invoke a metho | Dec 10, 2025 | 7.5 | 25 | NO | NO |
CVE-2019-6724HIGH The barracudavpn component of the Barracuda VPN Client prior to version 5.0.2.7 for Linux, macOS, and OpenBSD runs as a privileged process and can allow an unprivileged local attac | Mar 21, 2019 | 7.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Barracuda.
Media articles that mention a CVE ID that affects a product developed by Barracuda — matched by CVE ID, not by vendor name.