CVE-2025-34394: Barracuda Rmm

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, exposes a .NET Remoting service that is insufficiently protected against deserialization of arbitrary types. This can lead to remote code execution.

Affected products

  • Barracuda Rmm: before 2025.1.1 (fixed in 2025.1.1)

Published 2025-12-10. Last modified 2026-06-17.