Vendor CVEs
Veeam
All CVEs
93 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-40711 | Cri | 0.89 | 9.8 | 0.90 | KEV | Sep 7, 2024 | A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE). | |
| CVE-2022-26501 | Cri | 0.82 | 9.8 | 0.04 | KEV | Mar 17, 2022 | Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2). | |
| CVE-2022-26500 | Hig | 0.76 | 8.8 | 0.06 | KEV | Mar 17, 2022 | Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API functions that allows attackers to upload and execute arbitrary code. | |
| CVE-2020-10915 | Cri | 0.74 | 9.8 | 0.87 | Apr 22, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587. Authentication is not required to exploit this vulnerability. The specific flaw exists within the HandshakeResult method. The issue results from the lack… | ||
| CVE-2023-27532 | Hig | 0.73 | 7.5 | 0.78 | KEV | Mar 10, 2023 | Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead to gaining access to the backup infrastructure hosts. | |
| CVE-2020-10914 | Cri | 0.70 | 9.8 | 0.47 | Apr 22, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587. Authentication is not required to exploit this vulnerability. The specific flaw exists within the PerformHandshake method. The issue results from the… | ||
| CVE-2026-64633 | Cri | 0.65 | — | 0.00 | Aug 4, 2026 | A vulnerability allowing remote unauthenticated code execution on the agent host. | ||
| CVE-2024-29849 | Cri | 0.65 | 9.8 | 0.17 | May 22, 2024 | Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface. | ||
| CVE-2023-38547 | Cri | 0.65 | 9.8 | 0.19 | Nov 7, 2023 | A vulnerability in Veeam ONE allows an unauthenticated user to gain information about the SQL server connection Veeam ONE uses to access its configuration database. This may lead to remote code execution on the SQL server hosting the Veeam ONE configuration database. | ||
| CVE-2026-21708 | Cri | 0.64 | 9.9 | 0.01 | Mar 12, 2026 | A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user. | ||
| CVE-2026-21669 | Cri | 0.64 | 9.9 | 0.01 | Mar 12, 2026 | A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server. | ||
| CVE-2026-21667 | Cri | 0.64 | 9.9 | 0.01 | Mar 12, 2026 | A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server. | ||
| CVE-2026-21666 | Cri | 0.64 | 9.9 | 0.01 | Mar 12, 2026 | A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server. | ||
| CVE-2025-48983 | Cri | 0.64 | 9.9 | 0.01 | Oct 31, 2025 | A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructure hosts by an authenticated domain user. | ||
| CVE-2024-39714 | Cri | 0.64 | 9.9 | 0.01 | Sep 7, 2024 | A code injection vulnerability that permits a low-privileged user to upload arbitrary files to the server, leading to remote code execution on VSPC server. | ||
| CVE-2024-38650 | Cri | 0.64 | 9.9 | 0.01 | Sep 7, 2024 | An authentication bypass vulnerability can allow a low privileged attacker to access the NTLM hash of service account on the VSPC server. | ||
| CVE-2024-29212 | Cri | 0.64 | 9.9 | 0.02 | May 14, 2024 | Due to an unsafe de-serialization method used by the Veeam Service Provider Console(VSPC) server in communication between the management agent and its components, under certain conditions, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine. | ||
| CVE-2022-43549 | Cri | 0.64 | 9.8 | 0.01 | Dec 5, 2022 | Improper authentication in Veeam Backup for Google Cloud v1.0 and v3.0 allows attackers to bypass authentication mechanisms. | ||
| CVE-2021-35971 | Cri | 0.64 | 9.8 | 0.01 | Jun 30, 2021 | Veeam Backup and Replication 10 before 10.0.1.4854 P20210609 and 11 before 11.0.0.837 P20210507 mishandles deserialization during Microsoft .NET remoting. | ||
| CVE-2026-58073 | Cri | 0.62 | — | 0.00 | Aug 4, 2026 | A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials. | ||
| CVE-2026-44963 | Cri | 0.61 | — | 0.02 | Jun 9, 2026 | A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user. | ||
| CVE-2026-32998 | Cri | 0.61 | — | 0.00 | May 28, 2026 | This vulnerability in Veeam Service Provider Console allows for remote code execution. | ||
| CVE-2024-29855 | Cri | 0.60 | 9.0 | 0.22 | Jun 11, 2024 | Hard-coded JWT secret allows authentication bypass in Veeam Recovery Orchestrator | ||
| CVE-2019-11569 | Hig | 0.60 | 8.8 | 0.02 | May 6, 2019 | Veeam ONE Reporter 9.5.0.3201 allows CSRF. | ||
| CVE-2026-58072 | Cri | 0.59 | — | 0.00 | Aug 4, 2026 | A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead to remotecode execution. | ||
| CVE-2026-21671 | Cri | 0.59 | 9.1 | 0.01 | Mar 12, 2026 | A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availability (HA) deployments of Veeam Backup & Replication. | ||
| CVE-2025-59470 | Cri | 0.59 | 9.0 | 0.02 | Jan 8, 2026 | This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter. | ||
| CVE-2025-59469 | Cri | 0.59 | 9.0 | 0.01 | Jan 8, 2026 | This vulnerability allows a Backup or Tape Operator to write files as root. | ||
| CVE-2025-59468 | Cri | 0.59 | 9.0 | 0.01 | Jan 8, 2026 | This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending a malicious password parameter. | ||
| CVE-2025-23120 | Hig | 0.59 | 8.8 | 0.22 | Mar 20, 2025 | A vulnerability allowing remote code execution (RCE) for domain users. | ||
| CVE-2025-23114 | Cri | 0.59 | 9.0 | 0.01 | Feb 5, 2025 | A vulnerability in Veeam Updater component allows Man-in-the-Middle attackers to execute arbitrary code on the affected server. This issue occurs due to a failure to properly validate TLS certificate. | ||
| CVE-2025-23121 | Hig | 0.58 | 8.8 | 0.18 | Jun 19, 2025 | A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user | ||
| CVE-2026-21672 | Hig | 0.57 | 8.8 | 0.00 | Mar 12, 2026 | A vulnerability allowing local privilege escalation on Windows-based Veeam Backup & Replication servers. | ||
| CVE-2026-21668 | Hig | 0.57 | 8.8 | 0.01 | Mar 12, 2026 | A vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup Repository. | ||
| CVE-2025-48984 | Hig | 0.57 | 8.8 | 0.01 | Oct 31, 2025 | A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user. | ||
| CVE-2024-42456 | Hig | 0.57 | 8.8 | 0.00 | Dec 4, 2024 | A vulnerability in Veeam Backup & Replication platform allows a low-privileged user with a specific role to exploit a method that updates critical configuration settings, such as modifying the trusted client certificate used for authentication on a specific port. This can result… | ||
| CVE-2024-42452 | Hig | 0.57 | 8.8 | 0.00 | Dec 4, 2024 | A vulnerability in Veeam Backup & Replication allows a low-privileged user to start an agent remotely in server mode and obtain credentials, effectively escalating privileges to system-level access. This allows the attacker to upload files to the server with elevated privileges.… | ||
| CVE-2024-40717 | Hig | 0.57 | 8.8 | 0.01 | Dec 4, 2024 | A vulnerability in Veeam Backup & Replication allows a low-privileged user with certain roles to perform remote code execution (RCE) by updating existing jobs. These jobs can be configured to run pre- and post-scripts, which can be located on a network share and are executed… | ||
| CVE-2024-42024 | Hig | 0.57 | 8.8 | 0.01 | Sep 7, 2024 | A vulnerability that allows an attacker in possession of the Veeam ONE Agent service account credentials to perform remote code execution on the machine where the Veeam ONE Agent is installed. | ||
| CVE-2024-42023 | Hig | 0.57 | 8.8 | 0.00 | Sep 7, 2024 | An improper access control vulnerability allows low-privileged users to execute code with Administrator privileges remotely. | ||
| CVE-2024-40718 | Hig | 0.57 | 8.8 | 0.00 | Sep 7, 2024 | A server side request forgery vulnerability allows a low-privileged user to perform local privilege escalation through exploiting an SSRF vulnerability. | ||
| CVE-2024-40710 | Hig | 0.57 | 8.8 | 0.01 | Sep 7, 2024 | A series of related high-severity vulnerabilities, the most notable enabling remote code execution (RCE) as the service account and extraction of sensitive information (savedcredentials and passwords). Exploiting these vulnerabilities requires a user who has been assigned a… | ||
| CVE-2024-29850 | Hig | 0.57 | 8.8 | 0.01 | May 22, 2024 | Veeam Backup Enterprise Manager allows account takeover via NTLM relay. | ||
| CVE-2024-22022 | Hig | 0.57 | 8.8 | 0.01 | Feb 7, 2024 | Vulnerability CVE-2024-22022 allows a Veeam Recovery Orchestrator user that has been assigned a low-privileged role to access the NTLM hash of the service account used by the Veeam Orchestrator Server Service. | ||
| CVE-2022-26504 | Hig | 0.57 | 8.8 | 0.03 | Mar 17, 2022 | Improper authentication in Veeam Backup & Replication 9.5U3, 9.5U4,10.x and 11.x component used for Microsoft System Center Virtual Machine Manager (SCVMM) allows attackers execute arbitrary code via Veeam.Backup.PSManager.exe | ||
| CVE-2020-15518 | Hig | 0.57 | 8.8 | 0.01 | Jul 3, 2020 | VeeamFSR.sys in Veeam Availability Suite before 10 and Veeam Backup & Replication before 10 has no device object DACL, which allows unprivileged users to achieve total control over filesystem I/O requests. | ||
| CVE-2026-58074 | Hig | 0.56 | — | 0.00 | Aug 4, 2026 | A vulnerability allowing a high-privileged user to execute arbitrary code on the server. | ||
| CVE-2026-32997 | Hig | 0.56 | — | 0.01 | May 28, 2026 | A vulnerability allowing an authenticated user with the Backup Administrator role to write arbitrary files on Linux-based Veeam Backup & Replication server. | ||
| CVE-2026-64634 | Hig | 0.55 | — | 0.00 | Aug 4, 2026 | A vulnerability allowing local privilege escalation to the Reporter service context. | ||
| CVE-2024-38651 | Hig | 0.55 | 8.5 | 0.01 | Sep 7, 2024 | A code injection vulnerability can allow a low-privileged user to overwrite files on that VSPC server, which can lead to remote code execution on VSPC server. |
- risk 0.89cvss 9.8epss 0.90
A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).
- risk 0.82cvss 9.8epss 0.04
Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).
- risk 0.76cvss 8.8epss 0.06
Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API functions that allows attackers to upload and execute arbitrary code.
- risk 0.74cvss 9.8epss 0.87
This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587. Authentication is not required to exploit this vulnerability. The specific flaw exists within the HandshakeResult method. The issue results from the lack…
- risk 0.73cvss 7.5epss 0.78
Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead to gaining access to the backup infrastructure hosts.
- risk 0.70cvss 9.8epss 0.47
This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587. Authentication is not required to exploit this vulnerability. The specific flaw exists within the PerformHandshake method. The issue results from the…
- risk 0.65cvss —epss 0.00
A vulnerability allowing remote unauthenticated code execution on the agent host.
- risk 0.65cvss 9.8epss 0.17
Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface.
- risk 0.65cvss 9.8epss 0.19
A vulnerability in Veeam ONE allows an unauthenticated user to gain information about the SQL server connection Veeam ONE uses to access its configuration database. This may lead to remote code execution on the SQL server hosting the Veeam ONE configuration database.
- risk 0.64cvss 9.9epss 0.01
A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user.
- risk 0.64cvss 9.9epss 0.01
A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.
- risk 0.64cvss 9.9epss 0.01
A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.
- risk 0.64cvss 9.9epss 0.01
A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.
- risk 0.64cvss 9.9epss 0.01
A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructure hosts by an authenticated domain user.
- risk 0.64cvss 9.9epss 0.01
A code injection vulnerability that permits a low-privileged user to upload arbitrary files to the server, leading to remote code execution on VSPC server.
- risk 0.64cvss 9.9epss 0.01
An authentication bypass vulnerability can allow a low privileged attacker to access the NTLM hash of service account on the VSPC server.
- risk 0.64cvss 9.9epss 0.02
Due to an unsafe de-serialization method used by the Veeam Service Provider Console(VSPC) server in communication between the management agent and its components, under certain conditions, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine.
- risk 0.64cvss 9.8epss 0.01
Improper authentication in Veeam Backup for Google Cloud v1.0 and v3.0 allows attackers to bypass authentication mechanisms.
- risk 0.64cvss 9.8epss 0.01
Veeam Backup and Replication 10 before 10.0.1.4854 P20210609 and 11 before 11.0.0.837 P20210507 mishandles deserialization during Microsoft .NET remoting.
- risk 0.62cvss —epss 0.00
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials.
- risk 0.61cvss —epss 0.02
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.
- risk 0.61cvss —epss 0.00
This vulnerability in Veeam Service Provider Console allows for remote code execution.
- risk 0.60cvss 9.0epss 0.22
Hard-coded JWT secret allows authentication bypass in Veeam Recovery Orchestrator
- risk 0.60cvss 8.8epss 0.02
Veeam ONE Reporter 9.5.0.3201 allows CSRF.
- risk 0.59cvss —epss 0.00
A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead to remotecode execution.
- risk 0.59cvss 9.1epss 0.01
A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availability (HA) deployments of Veeam Backup & Replication.
- risk 0.59cvss 9.0epss 0.02
This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter.
- risk 0.59cvss 9.0epss 0.01
This vulnerability allows a Backup or Tape Operator to write files as root.
- risk 0.59cvss 9.0epss 0.01
This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending a malicious password parameter.
- risk 0.59cvss 8.8epss 0.22
A vulnerability allowing remote code execution (RCE) for domain users.
- risk 0.59cvss 9.0epss 0.01
A vulnerability in Veeam Updater component allows Man-in-the-Middle attackers to execute arbitrary code on the affected server. This issue occurs due to a failure to properly validate TLS certificate.
- risk 0.58cvss 8.8epss 0.18
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user
- risk 0.57cvss 8.8epss 0.00
A vulnerability allowing local privilege escalation on Windows-based Veeam Backup & Replication servers.
- risk 0.57cvss 8.8epss 0.01
A vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup Repository.
- risk 0.57cvss 8.8epss 0.01
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.
- risk 0.57cvss 8.8epss 0.00
A vulnerability in Veeam Backup & Replication platform allows a low-privileged user with a specific role to exploit a method that updates critical configuration settings, such as modifying the trusted client certificate used for authentication on a specific port. This can result…
- risk 0.57cvss 8.8epss 0.00
A vulnerability in Veeam Backup & Replication allows a low-privileged user to start an agent remotely in server mode and obtain credentials, effectively escalating privileges to system-level access. This allows the attacker to upload files to the server with elevated privileges.…
- risk 0.57cvss 8.8epss 0.01
A vulnerability in Veeam Backup & Replication allows a low-privileged user with certain roles to perform remote code execution (RCE) by updating existing jobs. These jobs can be configured to run pre- and post-scripts, which can be located on a network share and are executed…
- risk 0.57cvss 8.8epss 0.01
A vulnerability that allows an attacker in possession of the Veeam ONE Agent service account credentials to perform remote code execution on the machine where the Veeam ONE Agent is installed.
- risk 0.57cvss 8.8epss 0.00
An improper access control vulnerability allows low-privileged users to execute code with Administrator privileges remotely.
- risk 0.57cvss 8.8epss 0.00
A server side request forgery vulnerability allows a low-privileged user to perform local privilege escalation through exploiting an SSRF vulnerability.
- risk 0.57cvss 8.8epss 0.01
A series of related high-severity vulnerabilities, the most notable enabling remote code execution (RCE) as the service account and extraction of sensitive information (savedcredentials and passwords). Exploiting these vulnerabilities requires a user who has been assigned a…
- risk 0.57cvss 8.8epss 0.01
Veeam Backup Enterprise Manager allows account takeover via NTLM relay.
- risk 0.57cvss 8.8epss 0.01
Vulnerability CVE-2024-22022 allows a Veeam Recovery Orchestrator user that has been assigned a low-privileged role to access the NTLM hash of the service account used by the Veeam Orchestrator Server Service.
- risk 0.57cvss 8.8epss 0.03
Improper authentication in Veeam Backup & Replication 9.5U3, 9.5U4,10.x and 11.x component used for Microsoft System Center Virtual Machine Manager (SCVMM) allows attackers execute arbitrary code via Veeam.Backup.PSManager.exe
- risk 0.57cvss 8.8epss 0.01
VeeamFSR.sys in Veeam Availability Suite before 10 and Veeam Backup & Replication before 10 has no device object DACL, which allows unprivileged users to achieve total control over filesystem I/O requests.
- risk 0.56cvss —epss 0.00
A vulnerability allowing a high-privileged user to execute arbitrary code on the server.
- risk 0.56cvss —epss 0.01
A vulnerability allowing an authenticated user with the Backup Administrator role to write arbitrary files on Linux-based Veeam Backup & Replication server.
- risk 0.55cvss —epss 0.00
A vulnerability allowing local privilege escalation to the Reporter service context.
- risk 0.55cvss 8.5epss 0.01
A code injection vulnerability can allow a low-privileged user to overwrite files on that VSPC server, which can lead to remote code execution on VSPC server.
Page 1 of 2