CVE-2025-8319: Barracuda Message Archiver Firmware

Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.

the BMA login interface allows arbitrary JavaScript or HTML to be written straight into the page’s Document Object Model via the error= URL parameter

Affected products

  • Barracuda Message Archiver Firmware: version 5.4.2.002 only

Published 2025-07-30. Last modified 2026-06-17.