Skip to main content

Vendor/product archive

veeam / veeam_backup_&_replication CVEs

Beta · best-effort

42 CVEs tagged to veeam / veeam_backup_&_replication13 Critical, 24 High, 3 Medium, 2 Low, 0 Unrated.

CVE-2026-21671

Published Mar 12, 2026

A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availability (HA) deployments of Veeam Backup & Re…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-21667

Published Mar 12, 2026

A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.

CVSS 9.9 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-21666

Published Mar 12, 2026

A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.

CVSS 9.9 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-59470

Published Jan 8, 2026

This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter.

CVSS 9.0 · Critical
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2025-59468

Published Jan 8, 2026

This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending a malicious password parameter.

CVSS 9.0 · Critical
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2025-55125

Published Jan 8, 2026

This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious backup configuration file.

CVSS 7.8 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2025-48983

Published Oct 31, 2025

A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructure hosts by an authenticated domain user.

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-24286

Published Jun 19, 2025

A vulnerability allowing an authenticated user with the Backup Operator role to modify backup jobs, which could execute arbitrary code.

CVSS 7.2 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2024-45204

Published Dec 4, 2024

A vulnerability exists where a low-privileged user can exploit insufficient permissions in credential handling to leak NTLM hashes of saved credentials. The exploitation involves…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42457

Published Dec 4, 2024

A vulnerability in Veeam Backup & Replication allows users with certain operator roles to expose saved credentials by leveraging a combination of methods in a remote management in…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42456

Published Dec 4, 2024

A vulnerability in Veeam Backup & Replication platform allows a low-privileged user with a specific role to exploit a method that updates critical configuration settings, such as…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42455

Published Dec 4, 2024

A vulnerability in Veeam Backup & Replication allows a low-privileged user to connect to remoting services and exploit insecure deserialization by sending a serialized temporary f…

CVSS 8.1 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2024-42453

Published Dec 4, 2024

A vulnerability Veeam Backup & Replication allows low-privileged users to control and modify configurations on connected virtual infrastructure hosts. This includes the ability to…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42452

Published Dec 4, 2024

A vulnerability in Veeam Backup & Replication allows a low-privileged user to start an agent remotely in server mode and obtain credentials, effectively escalating privileges to s…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42451

Published Dec 4, 2024

A vulnerability in Veeam Backup & Replication allows low-privileged users to leak all saved credentials in plaintext. This is achieved by calling a series of methods over an exter…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-40717

Published Dec 4, 2024

A vulnerability in Veeam Backup & Replication allows a low-privileged user with certain roles to perform remote code execution (RCE) by updating existing jobs. These jobs can be c…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-40715

Published Nov 7, 2024

A vulnerability in Veeam Backup & Replication Enterprise Manager has been identified, which allows attackers to perform authentication bypass. Attackers must be able to perform Ma…

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 42 CVEsPage 1 of 2