Veeam Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with Veeam products.
Products
- One18 vulnerabilities
- Backup & Replication16 vulnerabilities
- Backup and Replication14 vulnerabilities
- Backup and Recovery13 vulnerabilities
- Service Provider Console10 vulnerabilities
- service_provider_console7 vulnerabilities
- backup_\&_replication6 vulnerabilities
- Veeam Service Provider Console5 vulnerabilities
- agent4 vulnerabilities
- backup_enterprise_manager4 vulnerabilities
- backup_and_replication3 vulnerabilities
- Recovery Orchestrator3 vulnerabilities
- Agent for Windows2 vulnerabilities
- Availability Orchestrator2 vulnerabilities
- Backup for Microsoft Azure2 vulnerabilities
- One Agent2 vulnerabilities
- Software Appliance2 vulnerabilities
- veeam_backup_\&_replication2 vulnerabilities
- Agent for Microsoft Windows1 vulnerability
- Backup and Recovery1 vulnerability
- Backup for AWS1 vulnerability
- Backup for Google Cloud1 vulnerability
- Backup for Microsoft Windows1 vulnerability
- Backup for Nutanix AHV1 vulnerability
- Backup for Oracle Linux Virtualization Manager and Red Hat Virtualization1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-58072CRITICAL | Generated title:Veeam Service Provider Console Arbitrary File Write to Remote Code ExecutionA vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead to remotecode execution. CWE-22Aug 4, 2026 | CVSS9.0v4.0 | EPSS0.376% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-58074HIGH | Generated title:Veeam ONE Code Injection VulnerabilityA vulnerability allowing a high-privileged user to execute arbitrary code on the server. CWE-94Aug 4, 2026 | CVSS8.6v4.0 | EPSS0.354% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-64630MEDIUM | Generated title:Veeam ONE Incorrect Authorization in Shared Report LinksA vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared report link. CWE-863Aug 4, 2026 | CVSS5.3v4.0 | EPSS0.236% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-58073CRITICAL | Generated title:Veeam Service Provider Console Authentication Bypass via ImpersonationA vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials. CWE-288Aug 4, 2026 | CVSS9.5v4.0 | EPSS0.224% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-64631HIGH | Generated title:Veeam ONE SQL Injection VulnerabilityA vulnerability allowing a low-privileged user to inject SQL and extract database contents. CWE-89Aug 4, 2026 | CVSS8.6v4.0 | EPSS0.266% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-58075HIGH | Generated title:Veeam ONE Unauthenticated Arbitrary File ReadA vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveraged toescalate privileges locally. CWE-287Aug 4, 2026 | CVSS8.7v4.0 | EPSS0.281% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-64633CRITICAL | Generated title:Veeam ONE Agent Unauthenticated Remote Code Execution VulnerabilityA vulnerability allowing remote unauthenticated code execution on the agent host. CWE-94Aug 4, 2026 | CVSS10.0v4.0 | EPSS0.337% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-64634HIGH | Generated title:Veeam ONE Local Privilege Escalation to Reporter Service ContextA vulnerability allowing local privilege escalation to the Reporter service context. CWE-269Aug 4, 2026 | CVSS8.4v4.0 | EPSS0.114% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-58071HIGH | Generated title:Veeam Service Provider Console Authentication Bypass via Proxied APIA vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API asPortal Administrator during a short window after an administrator session begins. CWE-306Aug 4, 2026 | CVSS8.2v4.0 | EPSS0.281% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-58067HIGH | Generated title:Veeam Service Provider Console Memory Allocation Denial of ServiceA vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause adenial of service. CWE-789Aug 4, 2026 | CVSS8.7v4.0 | EPSS0.3% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-64635MEDIUM | Generated title:Veeam Service Provider Console Forgot Password ReturnUrl Open Redirect and Account TakeoverImproper handling of the returnUrl parameter in the Forgot Password function of Veeam Service Provider Console allows an unauthenticated attacker to control the domain of the generated password reset link. When the targeted user clicks the link delivered by email, the reset code is transmitted to an attacker-controlled host, allowing the attacker to take over the account. CWE-640Jul 30, 2026 | CVSS5.3v3.1 | EPSS0.19% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-56844HIGH | Generated title:Veeam Backup and Replication Software Appliance Updater Local Privilege EscalationA vulnerability in the Veeam Updater component of the Veeam Software Appliance that could allow a local user to elevate their privileges and gain root-level access to the underlying operating system. CWE-22Jul 22, 2026 | CVSS8.4v4.0 | EPSS0.129% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-44963CRITICAL | Veeam veeam_backup_\&_replication Deserialization of Untrusted DataA vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user. CWE-502Jun 9, 2026 | CVSS9.4v4.0 | EPSS2.35% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-32998CRITICAL | Generated title:Veeam Service Provider Console Remote Code Execution VulnerabilityThis vulnerability in Veeam Service Provider Console allows for remote code execution. CWE-233May 28, 2026 | CVSS9.4v4.0 | EPSS0.403% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-32997HIGH | Generated title:Veeam Backup & Replication Authenticated Arbitrary File WriteA vulnerability allowing an authenticated user with the Backup Administrator role to write arbitrary files on Linux-based Veeam Backup & Replication server. CWE-36May 28, 2026 | CVSS8.6v4.0 | EPSS0.514% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-32996HIGH | Generated title:Veeam Agent for Microsoft Windows Local Privilege EscalationThis vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation. CWE-532May 28, 2026 | CVSS7.3v4.0 | EPSS0.154% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21709MEDIUM | Generated title:Veeam Backup and Replication Windows Driver Signature Enforcement BypassA vulnerability allowing a local attacker with administrator privileges to bypass Windows Driver Signature Enforcement. CWE-77Apr 17, 2026 | CVSS6.7v3.1 | EPSS0.171% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21708CRITICAL | Generated title:Veeam Backup & Replication SQL Injection Remote Code ExecutionA vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user. CWE-89Mar 12, 2026 | CVSS9.9v3.1 | EPSS1.09% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21672HIGH | Generated title:Veeam Backup & Replication Local Privilege EscalationA vulnerability allowing local privilege escalation on Windows-based Veeam Backup & Replication servers. CWE-538Mar 12, 2026 | CVSS8.8v3.1 | EPSS0.223% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21668HIGH | Generated title:Veeam Backup & Replication Authenticated Domain User Arbitrary File ManipulationA vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup Repository. | CVSS8.8v3.1 | EPSS0.51% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21669CRITICAL | Generated title:Veeam Backup and Replication Authenticated Remote Code ExecutionA vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server. | CVSS10.0v3.1 | EPSS1.17% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21671CRITICAL | Generated title:Veeam Backup & Replication Authenticated Remote Code Execution in High Availability DeploymentsA vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availability (HA) deployments of Veeam Backup & Replication. | CVSS9.1v3.1 | EPSS1.33% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21670HIGH | Generated title:Veeam Backup & Replication Insufficiently Protected SSH CredentialsA vulnerability allowing a low-privileged user to extract saved SSH credentials. CWE-522Mar 12, 2026 | CVSS7.7v3.1 | EPSS0.401% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21666CRITICAL | Generated title:Veeam Backup & Replication Remote Code ExecutionA vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server. CWE-284Mar 12, 2026 | CVSS10.0v3.1 | EPSS1.13% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-21667CRITICAL | Generated title:Veeam Backup and Replication Authenticated Remote Code ExecutionA vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server. CWE-284Mar 12, 2026 | CVSS10.0v3.1 | EPSS1.13% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |