Veeam Veeam provides backup, recovery, security software products
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Veeam product.
RSS Feeds for Veeam security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Veeam products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Veeam Sorted by Most Security Vulnerabilities since 2018
Known Exploited Veeam Vulnerabilities
The following Veeam vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| Veeam Backup and Replication Deserialization Vulnerability |
Veeam Backup and Replication contains a deserialization vulnerability allowing an unauthenticated user to perform remote code execution. CVE-2024-40711 Exploit Probability: 90.4% |
October 17, 2024 |
| Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability |
Veeam Backup & Replication Cloud Connect component contains a missing authentication for critical function vulnerability that allows an unauthenticated user operating within the backup infrastructure network perimeter to obtain encrypted credentials stored in the configuration database. This may lead to an attacker gaining access to the backup infrastructure hosts. CVE-2023-27532 Exploit Probability: 77.6% |
August 22, 2023 |
| Veeam Backup & Replication Remote Code Execution Vulnerability |
The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading and executing of malicious code. CVE-2022-26500 Exploit Probability: 5.8% |
December 13, 2022 |
| Veeam Backup & Replication Remote Code Execution Vulnerability |
The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading and executing of malicious code. CVE-2022-26501 Exploit Probability: 4.1% |
December 13, 2022 |
Of the known exploited vulnerabilities above, 2 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings.
By the Year
In 2026 there have been 29 vulnerabilities in Veeam with an average score of 8.6 out of ten. Last year, in 2025 Veeam had 7 security vulnerabilities published. That is, 22 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.33.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 29 | 8.59 |
| 2025 | 7 | 8.26 |
| 2024 | 32 | 7.62 |
| 2023 | 5 | 6.26 |
| 2022 | 5 | 8.66 |
| 2021 | 1 | 9.80 |
| 2020 | 2 | 0.00 |
| 2019 | 3 | 8.80 |
It may take a day or so for new Veeam vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Veeam Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-64633 | Aug 04, 2026 |
Remote Unauthenticated Code Execution on Agent Host CVE-2026-64633A vulnerability allowing remote unauthenticated code execution on the agent host. |
|
| CVE-2026-64631 | Aug 04, 2026 |
Low-Privileged User SQLi Enables Data Extraction in Unknown ProductA vulnerability allowing a low-privileged user to inject SQL and extract database contents. |
|
| CVE-2026-64630 | Aug 04, 2026 |
Low-Privileged User Reads Report Data Beyond Shared Link ScopeA vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared report link. |
|
| CVE-2026-58075 | Aug 04, 2026 |
Unauthenticated Local File Read & Priv Escalation via Host File AccessA vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveraged toescalate privileges locally. |
|
| CVE-2026-58074 | Aug 04, 2026 |
High-Priv Exec by High-Privileged User (CVE202658074)A vulnerability allowing a high-privileged user to execute arbitrary code on the server. |
|
| CVE-2026-58073 | Aug 04, 2026 |
Veeam Service Provider Console VSPC Auth Bypass: Air Gap Agent ImpersonationA vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials. |
|
| CVE-2026-58072 | Aug 04, 2026 |
Veeam SPC: Remote Code Exec via Arbitrary File WriteA vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead to remotecode execution. |
|
| CVE-2026-64634 | Aug 04, 2026 |
LPE via Reporter Service Context CVE-2026-64634A vulnerability allowing local privilege escalation to the Reporter service context. |
|
| CVE-2026-58067 | Aug 04, 2026 |
Veeam Service Provider Console: Unauthenticated Memory Exhaustion DoSA vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause adenial of service. |
|
| CVE-2026-58071 | Aug 04, 2026 |
Veeam SPC: Unauth API Access Post-LoginA vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API asPortal Administrator during a short window after an administrator session begins. |
|
| CVE-2026-64635 | Jul 30, 2026 |
Unauth Redirect via returnUrl in Veeam Service Provider ConsoleImproper handling of the returnUrl parameter in the Forgot Password function of Veeam Service Provider Console allows an unauthenticated attacker to control the domain of the generated password reset link. When the targeted user clicks the link delivered by email, the reset code is transmitted to an attacker-controlled host, allowing the attacker to take over the account. |
|
| CVE-2026-56844 | Jul 22, 2026 |
LPE via Veeam Updater in Veeam Software ApplianceA vulnerability in the Veeam Updater component of the Veeam Software Appliance that could allow a local user to elevate their privileges and gain root-level access to the underlying operating system. |
|
| CVE-2026-44963 | Jun 09, 2026 |
RCE via Authenticated Domain User on Backup ServerA vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user. |
|
| CVE-2026-32998 | May 28, 2026 |
Remote Code Execution (RCE) in Veeam Service Provider ConsoleThis vulnerability in Veeam Service Provider Console allows for remote code execution. |
|
| CVE-2026-32997 | May 28, 2026 |
Veeam Backup & Replication: Authenticated Arbitrary File Write (Linux)A vulnerability allowing an authenticated user with the Backup Administrator role to write arbitrary files on Linux-based Veeam Backup & Replication server. |
|
| CVE-2026-32996 | May 28, 2026 |
Veeam Agent LPE in Windows AgentThis vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation. |
|
| CVE-2026-21709 | Apr 17, 2026 |
Local Admin Bypass WDSE on Windows OSA vulnerability allowing a local attacker with administrator privileges to bypass Windows Driver Signature Enforcement. |
|
| CVE-2026-21708 | Mar 12, 2026 |
Backup Viewer RCE Exposes postgres User PrivilegesA vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user. |
|
| CVE-2026-21672 | Mar 12, 2026 |
Veeam Backup & Replication Windows LPEA vulnerability allowing local privilege escalation on Windows-based Veeam Backup & Replication servers. |
|
| CVE-2026-21671 | Mar 12, 2026 |
Veeam Backup & Rep RCE via HA Authenticated Backup AdminA vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availability (HA) deployments of Veeam Backup & Replication. |
|
| CVE-2026-21670 | Mar 12, 2026 |
Low-Privileged User Credential Extraction via SSHA vulnerability allowing a low-privileged user to extract saved SSH credentials. |
|
| CVE-2026-21669 | Mar 12, 2026 |
Windows Backup Server: Auth. Domain RCE via Remote Code ExecA vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server. |
|
| CVE-2026-21668 | Mar 12, 2026 |
Microsoft Windows Backup Repo: Authenticated Domain User Bypass File ManipulationA vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup Repository. |
|
| CVE-2026-21667 | Mar 12, 2026 |
Remote Code Execution in Backup Server via Authenticated Domain UserA vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server. |
|
| CVE-2026-21666 | Mar 12, 2026 |
Authenticated Domain User RCE on Backup ServerA vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server. |
|
| CVE-2025-59469 | Jan 08, 2026 |
PrivEsc: Backup/Tape Operator Escalates to Root via File WriteThis vulnerability allows a Backup or Tape Operator to write files as root. |
|
| CVE-2025-55125 | Jan 08, 2026 |
Root RCE via Malicious Backup Config in Veritas NetBackupThis vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious backup configuration file. |
|
| CVE-2025-59468 | Jan 08, 2026 |
RCE via Malicious Password Param in PostgreSQL Backup AdminThis vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending a malicious password parameter. |
|
| CVE-2025-59470 | Jan 08, 2026 |
PostgreSQL RCE via Malicious Interval/OrderThis vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter. |
|
| CVE-2025-48983 | Oct 30, 2025 |
Veeam Backup Mount Service RCE via Authenticated Domain UserA vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructure hosts by an authenticated domain user. |
|
| CVE-2025-48982 | Oct 30, 2025 |
Local Priv Escalation in Veeam Agent for Windows via Malicious RestoreThis vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation if a system administrator is tricked into restoring a malicious file. |
|
| CVE-2025-48984 | Oct 30, 2025 |
RCE in Microsoft Windows Backup Server via Authenticated Domain UserA vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user. |
|
| CVE-2025-24286 | Jun 19, 2025 |
Windows Server: Backup Operator Auth Esc for Arbitrary CodeA vulnerability allowing an authenticated user with the Backup Operator role to modify backup jobs, which could execute arbitrary code. |
|
| CVE-2025-23121 | Jun 19, 2025 |
RCE via authenticated domain user on Microsoft Windows Server BackupA vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user |
|
| CVE-2025-23120 | Mar 20, 2025 |
Win RCE for Domain Users via Remote ExploitA vulnerability allowing remote code execution (RCE) for domain users. |
|
| CVE-2025-23082 | Jan 14, 2025 |
Veeam Backup Azure SSRF: Unauth. Attacker Sends Unauthorized RequestsVeeam Backup for Microsoft Azure is vulnerable to Server-Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. |
|
| CVE-2024-45207 | Dec 04, 2024 |
Veeam Agent for Windows DLL Injection VulnerabilityDLL injection in Veeam Agent for Windows can occur if the system's PATH variable includes insecure locations. When the agent runs, it searches these directories for necessary DLLs. If an attacker places a malicious DLL in one of these directories, the Veeam Agent might load it inadvertently, allowing the attacker to execute harmful code. This could lead to unauthorized access, data theft, or disruption of services |
|
| CVE-2024-45206 | Dec 04, 2024 |
Veeam Service Provider Console SSRF VulnerabilityA vulnerability in Veeam Service Provider Console has been identified, which allows to perform arbitrary HTTP requests to arbitrary hosts of the network and get information about internal resources. |
|
| CVE-2024-45204 | Dec 04, 2024 |
Windows Credential Manager NTLM Hash Leak VulnerabilityA vulnerability exists where a low-privileged user can exploit insufficient permissions in credential handling to leak NTLM hashes of saved credentials. The exploitation involves using retrieved credentials to expose sensitive NTLM hashes, impacting systems beyond the initial target and potentially leading to broader security vulnerabilities. |
|
| CVE-2024-42457 | Dec 04, 2024 |
Veeam Backup & Replication: Remote Management Interface Credential Exposure VulnerabilityA vulnerability in Veeam Backup & Replication allows users with certain operator roles to expose saved credentials by leveraging a combination of methods in a remote management interface. This can be achieved using a session object that allows for credential enumeration and exploitation, leading to the leak of plaintext credentials to a malicious host. The attack is facilitated by improper usage of a method that allows operators to add a new host with an attacker-controlled IP, enabling them to retrieve sensitive credentials in plaintext. |
|
| CVE-2024-42456 | Dec 04, 2024 |
Veeam Backup & Replication: Insufficient Permission Control in Configuration Update MethodA vulnerability in Veeam Backup & Replication platform allows a low-privileged user with a specific role to exploit a method that updates critical configuration settings, such as modifying the trusted client certificate used for authentication on a specific port. This can result in unauthorized access, enabling the user to call privileged methods and initiate critical services. The issue arises due to insufficient permission requirements on the method, allowing users with low privileges to perform actions that should require higher-level permissions. |
|
| CVE-2024-42455 | Dec 04, 2024 |
Veeam Backup & Replication Insecure Deserialization VulnerabilityA vulnerability in Veeam Backup & Replication allows a low-privileged user to connect to remoting services and exploit insecure deserialization by sending a serialized temporary file collection. This exploit allows the attacker to delete any file on the system with service account privileges. The vulnerability is caused by an insufficient blacklist during the deserialization process. |
|
| CVE-2024-42453 | Dec 04, 2024 |
Veeam Backup & Replication: Improper Permission Checks in Management ServicesA vulnerability Veeam Backup & Replication allows low-privileged users to control and modify configurations on connected virtual infrastructure hosts. This includes the ability to power off virtual machines, delete files in storage, and make configuration changes, potentially leading to Denial of Service (DoS) and data integrity issues. The vulnerability is caused by improper permission checks in methods accessed via management services. |
|
| CVE-2024-42452 | Dec 04, 2024 |
Veeam Backup & Replication Remote Agent Privilege Escalation VulnerabilityA vulnerability in Veeam Backup & Replication allows a low-privileged user to start an agent remotely in server mode and obtain credentials, effectively escalating privileges to system-level access. This allows the attacker to upload files to the server with elevated privileges. The vulnerability exists because remote calls bypass permission checks, leading to full system compromise. |
|
| CVE-2024-42451 | Dec 04, 2024 |
Veeam Backup & Replication Credential Exposure VulnerabilityA vulnerability in Veeam Backup & Replication allows low-privileged users to leak all saved credentials in plaintext. This is achieved by calling a series of methods over an external protocol, ultimately retrieving the credentials using a malicious setup on the attacker's side. This exposes sensitive data, which could be used for further attacks, including unauthorized access to systems managed by the platform. |
|
| CVE-2024-40717 | Dec 04, 2024 |
Veeam Backup & Replication Remote Code Execution via Job UpdateA vulnerability in Veeam Backup & Replication allows a low-privileged user with certain roles to perform remote code execution (RCE) by updating existing jobs. These jobs can be configured to run pre- and post-scripts, which can be located on a network share and are executed with elevated privileges by default. The user can update a job and schedule it to run almost immediately, allowing arbitrary code execution on the server. |
|
| CVE-2024-40715 | Nov 07, 2024 |
Veeam Backup & Replication MITM Auth BypassA vulnerability in Veeam Backup & Replication Enterprise Manager has been identified, which allows attackers to perform authentication bypass. Attackers must be able to perform Man-in-the-Middle (MITM) attack to exploit this vulnerability. |
|
| CVE-2024-39718 | Sep 07, 2024 |
IIV permits low-privileged user to delete files as service acc.An improper input validation vulnerability that allows a low-privileged user to remotely remove files on the system with permissions equivalent to those of the service account. |
|
| CVE-2024-42020 | Sep 07, 2024 |
XSS in Reporter Widgets via HTML injectionA Cross-site-scripting (XSS) vulnerability exists in the Reporter Widgets that allows HTML injection. |
|
| CVE-2024-40711 | Sep 07, 2024 |
Unauthenticated RCE via deserialization in Unknown ComponentA deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE). |
|