CVE Tools

Veeam-software-ag

26 CVEs tracked since 2024. Since Sep 2024, 1 of them reached CISA KEV.

Veeam-software-ag CVEs per month

Sep 2024 to Dec 2024. Point at a month, or focus the strip and use the arrow keys.
Veeam-software-ag CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2024-09171
2024-10null or fewer
2024-11null or fewer
2024-1290

Products

The products that kept showing up in Veeam-software-ag's monthly top three, with their CVEs summed over those months.

  1. Veeam Backup & Replication112 months
  2. Veeam Service Provider Console (Vspc)72 months
  3. Veeam One61 month
  4. Veeam Agent For Microsoft Windows11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Veeam-software-ag.

  1. CVE-2026-21669A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.9.9
  2. CVE-2026-21667A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.9.9
  3. CVE-2026-21666A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.9.9
  4. CVE-2026-21671A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availability (HA) deployments of Veeam Backup & Replication.9.1
  5. CVE-2025-48983A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructure hosts by an authenticated domain user.9.9
  6. CVE-2025-48982This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation if a system administrator is tricked into restoring a malicious file.7.8
  7. CVE-2025-48984A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.8.8
  8. CVE-2025-23121A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user8.8
  9. CVE-2025-23120A vulnerability allowing remote code execution (RCE) for domain users.8.8
  10. CVE-2025-23114A vulnerability in Veeam Updater component allows Man-in-the-Middle attackers to execute arbitrary code on the affected server. This issue occurs due to a failure to properly validate TLS certificate.9.0
  11. CVE-2025-23082Veeam Backup for Microsoft Azure is vulnerable to Server-Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading t...7.2
  12. CVE-2024-42448From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine.9.9
  13. CVE-2024-45206A vulnerability in Veeam Service Provider Console has been identified, which allows to perform arbitrary HTTP requests to arbitrary hosts of the network and get information about internal resources.6.5
  14. CVE-2024-45207DLL injection in Veeam Agent for Windows can occur if the system's PATH variable includes insecure locations. When the agent runs, it searches these directories for necessary DLLs. If an attacker p...7.0
  15. CVE-2024-42453A vulnerability Veeam Backup & Replication allows low-privileged users to control and modify configurations on connected virtual infrastructure hosts. This includes the ability to power off virtual...8.1

The record

Peak rank
#44 in Sep 2024
Busiest month shown
Sep 2024, 17 CVEs
Months with a KEV entry
1 since Sep 2024
Monthly snapshots
2 since 2024
Veeam-software-ag's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store