⚡ Exploit-DB.ai CRITICAL
CRITICAL

CVE-2023-2868

Published: March 18, 2026 · Source: National Vulnerability Database (NVD)

⚡ AI Threat Assessment

Barracuda ESG zero-day exploited since October 2022 by UNC4841 (China-nexus APT) in mass campaign against government and defense organizations. Barracuda recommended REPLACING physical appliances — patch was insufficient. This is an extremely severe supply-chain-adjacent attack.

📋 Official Description

Barracuda Email Security Gateway (ESG) appliance had a remote code execution vulnerability due to incomplete input validation of file names in TAR archive attachments.

Get Real-Time CVE Alerts

Supernova subscribers receive AI-triaged CVE alerts the moment they're published — before the PoC drops.

Start Supernova — $99/mo →