Cyber Alerts

Barracuda Email Security Gateway (ESG) Zero Day Vulnerability

Verified Officially confirmed Active exploitation confirmed

National Cyber Coordination and Command Centre (NC4) is aware of active exploitation on Barracuda Email Security Gateway (ESG) vulnerabilities that could allow an attacker to gain control of an affected system, install backdoors and exfiltrate data. The impact of these vulnerabilities is critical as it was observed can be utilised as vector for espionage activities.

First observed
13 Jul 2023
Last checked
01 Aug 2026
Evidence records
1
Publication state
Published

What happened?

Current assessment

National Cyber Coordination and Command Centre (NC4) is aware of active exploitation on Barracuda Email Security Gateway (ESG) vulnerabilities that could allow an attacker to gain control of an affected system, install backdoors and exfiltrate data. The impact of these vulnerabilities is critical as it was observed can be utilised as vector for espionage activities.

Why it matters

Information leakage, malware infection.

Who is affected?

Affected products and groups

No affected entity has been safely confirmed in the structured record yet.

What should you do now?

Actions from official guidance

For technical teams

  1. According to Barracuda[1], organisations should discontinue the use of the compromised ESG appliance and contact Barracuda support (support@barracuda.com) to replace it with a new ESG virtual or hardware appliance. Impacted organisations should also review their environments and determine any additional actions they need to take including review their enterprise privileged credentials like Active Directory that were used to manage the affected Barracuda appliance. NC4 also advise organisations to validate the use and behaviour of all credentials used on the appliance. Official source
  2. Organisations are also advised to be vigilant and to take the following actions: Official source
  3. Sweep impacted environment for IOCs Review email logs to identify the initial point of exposure Revoke and rotate all local and domain-based credentials that were on the ESG Revoke and reissue all certificates on the ESG Monitor the environment for the use of credentials Monitor the environment for use of certificates Review network logs for signs of data exfiltration and lateral movement Image the ESG appliance and conduct a forensic analysis Report any anomalies happening within your network and enterprise environment to NC4 Official source

Which sources support it?

Evidence and official sources

  1. NACSA / NC4 Alerts and AdvisoriesOfficial source
    Barracuda Email Security Gateway (ESG) Zero Day Vulnerability

    National Cyber Coordination and Command Centre (NC4) is aware of active exploitation on Barracuda Email Security Gateway (ESG) vulnerabilities that could allow an attacker to gain control of an affected system, install backdoors and exfiltrate data. The impact of these vulnerabilities is critical as it was observed can be utilised as vector for espionage activities.

    Published 13 Jul 2023 · Retrieved 01 Aug 2026