VYPR

Veeam Backup \& Replication

by Veeam

CVEs (47)

  • CVE-2024-40711CriKEVSep 7, 2024
    risk 0.89cvss 9.8epss 0.90

    A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).

  • CVE-2022-26501CriKEVMar 17, 2022
    risk 0.82cvss 9.8epss 0.04

    Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).

  • CVE-2022-26500HigKEVMar 17, 2022
    risk 0.76cvss 8.8epss 0.06

    Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API functions that allows attackers to upload and execute arbitrary code.

  • CVE-2023-27532HigKEVMar 10, 2023
    risk 0.73cvss 7.5epss 0.78

    Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead to gaining access to the backup infrastructure hosts.

  • CVE-2024-29849CriMay 22, 2024
    risk 0.65cvss 9.8epss 0.17

    Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface.

  • CVE-2026-21708CriMar 12, 2026
    risk 0.64cvss 9.9epss 0.01

    A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user.

  • CVE-2026-21669CriMar 12, 2026
    risk 0.64cvss 9.9epss 0.01

    A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.

  • CVE-2026-21667CriMar 12, 2026
    risk 0.64cvss 9.9epss 0.01

    A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.

  • CVE-2026-21666CriMar 12, 2026
    risk 0.64cvss 9.9epss 0.01

    A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.

  • CVE-2025-48983CriOct 31, 2025
    risk 0.64cvss 9.9epss 0.01

    A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructure hosts by an authenticated domain user.

  • CVE-2021-35971CriJun 30, 2021
    risk 0.64cvss 9.8epss 0.01

    Veeam Backup and Replication 10 before 10.0.1.4854 P20210609 and 11 before 11.0.0.837 P20210507 mishandles deserialization during Microsoft .NET remoting.

  • CVE-2026-21671CriMar 12, 2026
    risk 0.59cvss 9.1epss 0.01

    A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availability (HA) deployments of Veeam Backup & Replication.

  • CVE-2025-59470CriJan 8, 2026
    risk 0.59cvss 9.0epss 0.02

    This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter.

  • CVE-2025-59469CriJan 8, 2026
    risk 0.59cvss 9.0epss 0.01

    This vulnerability allows a Backup or Tape Operator to write files as root.

  • CVE-2025-59468CriJan 8, 2026
    risk 0.59cvss 9.0epss 0.01

    This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending a malicious password parameter.

  • CVE-2025-23120HigMar 20, 2025
    risk 0.59cvss 8.8epss 0.22

    A vulnerability allowing remote code execution (RCE) for domain users.

  • CVE-2025-23121HigJun 19, 2025
    risk 0.58cvss 8.8epss 0.18

    A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user

  • CVE-2026-21672HigMar 12, 2026
    risk 0.57cvss 8.8epss 0.00

    A vulnerability allowing local privilege escalation on Windows-based Veeam Backup & Replication servers.

  • CVE-2026-21668HigMar 12, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup Repository.

  • CVE-2025-48984HigOct 31, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.

Page 1 of 3