Products

Showing 25 vulnerabilities on this page

Signals CISA KEV Ransomware Nuclei
Veeam vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Generated title:Veeam Service Provider Console Arbitrary File Write to Remote Code Execution

A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead to remotecode execution.

CWE-22Aug 4, 2026
CVSS9.0v4.0EPSS0.376%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Veeam ONE Code Injection Vulnerability

A vulnerability allowing a high-privileged user to execute arbitrary code on the server.

CWE-94Aug 4, 2026
CVSS8.6v4.0EPSS0.354%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Veeam ONE Incorrect Authorization in Shared Report Links

A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared report link.

CWE-863Aug 4, 2026
CVSS5.3v4.0EPSS0.236%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Veeam Service Provider Console Authentication Bypass via Impersonation

A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials.

CWE-288Aug 4, 2026
CVSS9.5v4.0EPSS0.224%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Veeam ONE SQL Injection Vulnerability

A vulnerability allowing a low-privileged user to inject SQL and extract database contents.

CWE-89Aug 4, 2026
CVSS8.6v4.0EPSS0.266%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Veeam ONE Unauthenticated Arbitrary File Read

A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveraged toescalate privileges locally.

CWE-287Aug 4, 2026
CVSS8.7v4.0EPSS0.281%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Veeam ONE Agent Unauthenticated Remote Code Execution Vulnerability

A vulnerability allowing remote unauthenticated code execution on the agent host.

CWE-94Aug 4, 2026
CVSS10.0v4.0EPSS0.337%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Veeam ONE Local Privilege Escalation to Reporter Service Context

A vulnerability allowing local privilege escalation to the Reporter service context.

CWE-269Aug 4, 2026
CVSS8.4v4.0EPSS0.114%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Veeam Service Provider Console Authentication Bypass via Proxied API

A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API asPortal Administrator during a short window after an administrator session begins.

CWE-306Aug 4, 2026
CVSS8.2v4.0EPSS0.281%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Veeam Service Provider Console Memory Allocation Denial of Service

A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause adenial of service.

CWE-789Aug 4, 2026
CVSS8.7v4.0EPSS0.3%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Veeam Service Provider Console Forgot Password ReturnUrl Open Redirect and Account Takeover

Improper handling of the returnUrl parameter in the Forgot Password function of Veeam Service Provider Console allows an unauthenticated attacker to control the domain of the generated password reset link. When the targeted user clicks the link delivered by email, the reset code is transmitted to an attacker-controlled host, allowing the attacker to take over the account.

CWE-640Jul 30, 2026
CVSS5.3v3.1EPSS0.19%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Veeam Backup and Replication Software Appliance Updater Local Privilege Escalation

A vulnerability in the Veeam Updater component of the Veeam Software Appliance that could allow a local user to elevate their privileges and gain root-level access to the underlying operating system.

CWE-22Jul 22, 2026
CVSS8.4v4.0EPSS0.129%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Veeam veeam_backup_\&_replication Deserialization of Untrusted Data

A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.

CWE-502Jun 9, 2026
CVSS9.4v4.0EPSS2.35%PoCs2SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Veeam Service Provider Console Remote Code Execution Vulnerability

This vulnerability in Veeam Service Provider Console allows for remote code execution.

CWE-233May 28, 2026
CVSS9.4v4.0EPSS0.403%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Veeam Backup & Replication Authenticated Arbitrary File Write

A vulnerability allowing an authenticated user with the Backup Administrator role to write arbitrary files on Linux-based Veeam Backup & Replication server.

CWE-36May 28, 2026
CVSS8.6v4.0EPSS0.514%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Veeam Agent for Microsoft Windows Local Privilege Escalation

This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.

CWE-532May 28, 2026
CVSS7.3v4.0EPSS0.154%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Veeam Backup and Replication Windows Driver Signature Enforcement Bypass

A vulnerability allowing a local attacker with administrator privileges to bypass Windows Driver Signature Enforcement.

CWE-77Apr 17, 2026
CVSS6.7v3.1EPSS0.171%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Veeam Backup & Replication SQL Injection Remote Code Execution

A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user.

CWE-89Mar 12, 2026
CVSS9.9v3.1EPSS1.09%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Veeam Backup & Replication Local Privilege Escalation

A vulnerability allowing local privilege escalation on Windows-based Veeam Backup & Replication servers.

CWE-538Mar 12, 2026
CVSS8.8v3.1EPSS0.223%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Veeam Backup & Replication Authenticated Domain User Arbitrary File Manipulation

A vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup Repository.

CWE-693CWE-862Mar 12, 2026
CVSS8.8v3.1EPSS0.51%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Veeam Backup and Replication Authenticated Remote Code Execution

A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.

CWE-693CWE-94Mar 12, 2026
CVSS10.0v3.1EPSS1.17%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Veeam Backup & Replication Authenticated Remote Code Execution in High Availability Deployments

A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availability (HA) deployments of Veeam Backup & Replication.

CWE-693CWE-94Mar 12, 2026
CVSS9.1v3.1EPSS1.33%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Veeam Backup & Replication Insufficiently Protected SSH Credentials

A vulnerability allowing a low-privileged user to extract saved SSH credentials.

CWE-522Mar 12, 2026
CVSS7.7v3.1EPSS0.401%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Veeam Backup & Replication Remote Code Execution

A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.

CWE-284Mar 12, 2026
CVSS10.0v3.1EPSS1.13%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Veeam Backup and Replication Authenticated Remote Code Execution

A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.

CWE-284Mar 12, 2026
CVSS10.0v3.1EPSS1.13%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX