Barracuda disclosed that its Email Security Gateway appliances were compromised through CVE-2023-2868, a zero-day in the Amavis antivirus scanning module that improperly sanitized .tar file contents in email attachments, enabling remote command execution and full takeover of affected physical appliances. The flaw affected ESG versions 5.1.3.001 through 9.2.0.006, and Barracuda issued patch BNSF-36456; however, the company and outside researchers warned that patching alone was insufficient because attackers could maintain persistence after exploitation, leading Barracuda to advise customers to replace impacted hardware rather than simply update it.
Reporting from Mandiant, Rapid7, KrebsOnSecurity, The Record, and government advisories said the intrusions were linked to a China-backed espionage group and involved multiple backdoors and implants, including SALTWATER, SEASIDE, SEASPY, SEASPY v2, WHIRPOOL, and SEASPRAY. CISA highlighted the incident as evidence of persistent risk at the network edge, while responders urged organizations to rotate credentials, reissue certificates, hunt for indicators of compromise, investigate lateral movement, and assess possible data exfiltration from any exposed Barracuda ESG device.

See which actors are running it and whether you're in range.
9 events from the most recent confirmed update back to the earliest known activity.
Barracuda published a legal notice about the ESG vulnerability and the company's response. The notice served as a formal public reference for the incident and remediation guidance.
NACSA published an advisory warning of active exploitation of CVE-2023-2868 and summarizing associated malware, espionage activity, and remediation steps. The notice reiterated that compromised appliances should be replaced and that organizations should rotate credentials, reissue certificates, and investigate for lateral movement and exfiltration.
Rapid7 published technical analysis warning that CVE-2023-2868 could lead to total compromise of physical Barracuda ESG appliances. The report highlighted the severity of the flaw and the difficulty of trusting impacted hardware after exploitation.
Mandiant attributed the Barracuda ESG exploitation campaign to UNC4841, a China-nexus espionage actor. Reporting described deployment of backdoors including SALTWATER, SEASIDE, and SEASPY, along with theft of email data and SSL certificates.
A CISA order drew attention to the Barracuda ESG incident as an example of persistent risk from compromised network-edge devices. The action underscored concerns that patching alone may not remove attacker access from affected appliances.
Barracuda advised customers that compromised ESG appliances must be replaced immediately rather than trusted after patching. The company recommended discontinuing use of affected devices and contacting support for replacement hardware or virtual appliances.
Barracuda released patch BNSF-36456 to address CVE-2023-2868 on affected Email Security Gateway appliances. The patch was applied to impacted versions, but later guidance warned it was insufficient for already-compromised devices.
Barracuda stated it became aware of the vulnerability in May 2023 while it was being actively exploited. The issue affected ESG appliance versions 5.1.3.001 through 9.2.0.006.
CVE-2023-2868 in Barracuda Email Security Gateway appliances was exploited in the wild as early as October 2022. The flaw enabled remote command execution via crafted .tar file attachments processed by the Amavis module.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
8 references tracked. Mallory keeps watching after this page renders.
barracuda.com
Open sourcenacsa.gov.my
Open sourcetherecord.media
Open sourcekrebsonsecurity.com
Open sourcerapid7.com
Open sourcekrebsonsecurity.com
Open sourcetherecord.media
Open sourcemandiant.widen.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.