CVE Tools

Veeam Backup \& Replication

42 CVEs tracked. 4 of them are in CISA KEV.

This hub aggregates every CVE we track for Veeam Backup \& Replication, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.

Veeam Backup \& Replication CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Veeam Backup \& Replication CVEs per month
MonthCVEs
2024-100
2024-111
2024-128
2025-010
2025-020
2025-031
2025-040
2025-050
2025-062
2025-070
2025-080
2025-090
2025-102
2025-110
2025-120
2026-014
2026-020
2026-037
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 42 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical1331%
  • High2457%
  • Medium37%
  • Low25%

Latest CVEs

The 15 most recently published vulnerabilities affecting Veeam Backup \& Replication.

  1. CVE-2026-21708A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user.9.9
  2. CVE-2026-21669A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.9.9
  3. CVE-2026-21667A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.9.9
  4. CVE-2026-21670A vulnerability allowing a low-privileged user to extract saved SSH credentials.7.7
  5. CVE-2026-21668A vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup Repository.8.8
  6. CVE-2026-21666A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.9.9
  7. CVE-2026-21671A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availability (HA) deployments of Veeam Backup & Replication.9.1
  8. CVE-2025-55125This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious backup configuration file.7.8
  9. CVE-2025-59469This vulnerability allows a Backup or Tape Operator to write files as root.9.0
  10. CVE-2025-59468This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending a malicious password parameter.9.0
  11. CVE-2025-59470This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter.9.0
  12. CVE-2025-48983A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructure hosts by an authenticated domain user.9.9
  13. CVE-2025-48984A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.8.8
  14. CVE-2025-24286A vulnerability allowing an authenticated user with the Backup Operator role to modify backup jobs, which could execute arbitrary code.7.2
  15. CVE-2025-23121A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user8.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store