Cyber Alerts
Barracuda Email Security Gateway (ESG) Zero Day Vulnerability
National Cyber Coordination and Command Centre (NC4) is aware of active exploitation on Barracuda Email Security Gateway (ESG) vulnerabilities that could allow an attacker to gain control of an affected system, install backdoors and exfiltrate data. The impact of these vulnerabilities is critical as it was observed can be utilised as vector for espionage activities.
- First observed
- 13 Jul 2023
- Last checked
- 01 Aug 2026
- Evidence records
- 1
- Publication state
- Published
What happened?
Current assessment
National Cyber Coordination and Command Centre (NC4) is aware of active exploitation on Barracuda Email Security Gateway (ESG) vulnerabilities that could allow an attacker to gain control of an affected system, install backdoors and exfiltrate data. The impact of these vulnerabilities is critical as it was observed can be utilised as vector for espionage activities.
Why it matters
Information leakage, malware infection.
Who is affected?
Affected products and groups
No affected entity has been safely confirmed in the structured record yet.
What should you do now?
Actions from official guidance
For technical teams
- According to Barracuda[1], organisations should discontinue the use of the compromised ESG appliance and contact Barracuda support (support@barracuda.com) to replace it with a new ESG virtual or hardware appliance. Impacted organisations should also review their environments and determine any additional actions they need to take including review their enterprise privileged credentials like Active Directory that were used to manage the affected Barracuda appliance. NC4 also advise organisations to validate the use and behaviour of all credentials used on the appliance. Official source
- Organisations are also advised to be vigilant and to take the following actions: Official source
- Sweep impacted environment for IOCs Review email logs to identify the initial point of exposure Revoke and rotate all local and domain-based credentials that were on the ESG Revoke and reissue all certificates on the ESG Monitor the environment for the use of credentials Monitor the environment for use of certificates Review network logs for signs of data exfiltration and lateral movement Image the ESG appliance and conduct a forensic analysis Report any anomalies happening within your network and enterprise environment to NC4 Official source
Which sources support it?
Evidence and official sources
-
NACSA / NC4 Alerts and AdvisoriesOfficial sourceBarracuda Email Security Gateway (ESG) Zero Day Vulnerability
National Cyber Coordination and Command Centre (NC4) is aware of active exploitation on Barracuda Email Security Gateway (ESG) vulnerabilities that could allow an attacker to gain control of an affected system, install backdoors and exfiltrate data. The impact of these vulnerabilities is critical as it was observed can be utilised as vector for espionage activities.
Published 13 Jul 2023 · Retrieved 01 Aug 2026