<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>0dayNews — Barracuda Networks</title><description>Vulnerabilities in Barracuda Networks&apos; Email Security Gateway appliances — internet-facing mail-scanning devices that, once compromised, gave attackers a foothold that in one case survived even after patching. Combined article + CVE feed for the Barracuda Networks beat.</description><link>https://0daynews.com/</link><language>en-us</language><item><title>CVE-2023-2868 — Barracuda Email Security Gateway Zero-Day Remote Command Injection</title><link>https://0daynews.com/cve/cve-2023-2868/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-2868/</guid><description>A remote command-injection vulnerability in Barracuda Email Security Gateway (ESG) appliances, exploited as a zero-day for at least seven months before discovery, allowed attackers to gain a persistent backdoor — remediation required full physical appliance replacement, not just a patch, in confirmed-compromised units.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Barracuda Networks</category><category>critical</category><category>cve</category></item><item><title>Barracuda Told Customers to Replace ESG Appliances</title><link>https://0daynews.com/articles/2026-07-05-barracuda-esg-zero-day-cve-2023-2868/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-05-barracuda-esg-zero-day-cve-2023-2868/</guid><description>CVE-2023-2868 was exploited as a zero-day for roughly seven months before discovery — and left some compromised appliances backdoored even after the software patch was applied.</description><pubDate>Sun, 05 Jul 2026 15:30:00 GMT</pubDate><category>Barracuda Networks</category><category>article</category></item></channel></rss>