CVE Tools

Barracuda

4 CVEs tracked since 2015. Since May 2015, none of them reached CISA KEV.

Barracuda CVEs per month

May 2015 to Aug 2017. Point at a month, or focus the strip and use the arrow keys.
Barracuda CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2015-0520
2015-06null or fewer
2015-07null or fewer
2015-08null or fewer
2015-09null or fewer
2015-10null or fewer
2015-11null or fewer
2015-12null or fewer
2016-01null or fewer
2016-02null or fewer
2016-03null or fewer
2016-04null or fewer
2016-05null or fewer
2016-06null or fewer
2016-07null or fewer
2016-08null or fewer
2016-09null or fewer
2016-10null or fewer
2016-11null or fewer
2016-12null or fewer
2017-01null or fewer
2017-02null or fewer
2017-03null or fewer
2017-04null or fewer
2017-05null or fewer
2017-06null or fewer
2017-07null or fewer
2017-0820

Products

The products that kept showing up in Barracuda's monthly top three, with their CVEs summed over those months.

  1. Load Balancer21 month
  2. Web Filter21 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Barracuda.

  1. CVE-2025-34395Barracuda RMM < 2025.1.1 Service Center .NET Remoting Path Traversal RCE7.5
  2. CVE-2025-34394Barracuda RMM < 2025.1.1 Service Center .NET Remoting Deserialization RCE9.8
  3. CVE-2025-34393Barracuda RMM < 2025.1.1 Service Center Insecure Reflection RCE9.8
  4. CVE-2025-34392Barracuda RMM < 2025.1.1 Service Center Absolute Path Traversal RCE9.8
  5. CVE-2025-8319the BMA login interface allows arbitrary JavaScript or HTML to be written straight into the page’s Document Object Model via the error= URL parameter6.1
  6. CVE-2023-7102Remote Code Execution (RCE) Vulnerability9.8
  7. CVE-2023-2868Remote Code injection in Barracuda Email Security Gateway9.4
  8. CVE-2023-26213On Barracuda CloudGen WAN Private Edge Gateway devices before 8 webui-sdwan-1089-8.3.1-174141891, an OS command injection vulnerability exists in /ajax/update_certificate - a crafted HTTP request a...7.2
  9. CVE-2021-42711Barracuda Network Access Client before 5.2.2 creates a Temporary File in a Directory with Insecure Permissions. This file is executed with SYSTEM privileges when an unprivileged user performs a rep...7.8
  10. CVE-2019-5648LDAP Credential Exposure in Barracuda Load Balancer ADC6.5
  11. CVE-2014-2595Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a permanent authentication token obtained from a query string.9.8
  12. CVE-2019-6724The barracudavpn component of the Barracuda VPN Client prior to version 5.0.2.7 for Linux, macOS, and OpenBSD runs as a privileged process and can allow an unprivileged local attacker to load a mal...7.8
  13. CVE-2018-20369Barracuda Message Archiver 2018 has XSS in the error_msg exception-handling value for the ldap_user parameter to the cgi-mod/ldap_load_entry.cgi module. The injection point of the issue is the Add_...6.1
  14. CVE-2014-8428Privilege escalation vulnerability in Barracuda Load Balancer 5.0.0.015 via the use of an improperly protected SSH key.9.8
  15. CVE-2014-8426Hard coded weak credentials in Barracuda Load Balancer 5.0.0.015.9.8

The record

Peak rank
#39 in May 2015
Busiest month shown
May 2015, 2 CVEs
Months with a KEV entry
0 since May 2015
Monthly snapshots
2 since 2015
Barracuda's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store