← Back

Veeam

veeam

71 CVEs • 14 products

Products (14)

Click to collapse
Toggle

CVEs (71)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Veeam
1Veeam Backup & Replication
Jun 17, 2026
Mar 12, 2026
N/A· v4
9.9 CRITICAL· v3
N/A· v2
A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user.
1Veeam
1Veeam Backup & Replication
Jun 17, 2026
Mar 12, 2026
N/A· v4
9.1 CRITICAL· v3
N/A· v2
A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availability (HA) deployments of Veeam Backup & Replication.
1Veeam
1Veeam Backup & Replication
Jun 17, 2026
Mar 12, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A vulnerability allowing a low-privileged user to extract saved SSH credentials.
1Veeam
1Veeam Backup & Replication
Jun 17, 2026
Mar 12, 2026
N/A· v4
9.9 CRITICAL· v3
N/A· v2
A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.
1Veeam
1Veeam Backup & Replication
Jun 17, 2026
Mar 12, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup Repository.
1Veeam
1Veeam Backup & Replication
Jun 17, 2026
Mar 12, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.
1Veeam
1Veeam Backup & Replication
Jun 17, 2026
Mar 12, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.
1Veeam
1Veeam Backup & Replication
Jun 17, 2026
Jan 8, 2026
N/A· v4
9.0 CRITICAL· v3
N/A· v2
This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter.
1Veeam
1Veeam Backup & Replication
Jun 17, 2026
Jan 8, 2026
N/A· v4
9.0 CRITICAL· v3
N/A· v2
This vulnerability allows a Backup or Tape Operator to write files as root.
1Veeam
1Veeam Backup & Replication
Jun 17, 2026
Jan 8, 2026
N/A· v4
9.1 CRITICAL· v3
N/A· v2
This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending a malicious password parameter.
1Veeam
1Veeam Backup & Replication
Jun 17, 2026
Jan 8, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious backup configuration file.
1Veeam
1Veeam Backup & Replication
Jun 17, 2026
Oct 31, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.
1Veeam
1Veeam Backup & Replication
Jun 17, 2026
Oct 31, 2025
N/A· v4
9.9 CRITICAL· v3
N/A· v2
A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructure hosts by an authenticated domain user.
1Veeam
1Veeam Agent For Windows
Jun 17, 2026
Oct 31, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation if a system administrator is tricked into restoring a malicious file.
1Veeam
1Veeam Backup & Replication
Jun 17, 2026
Jun 19, 2025
N/A· v4
4.9 MEDIUM· v3
N/A· v2
A vulnerability allowing an authenticated user with the Backup Operator role to modify backup jobs, which could execute arbitrary code.
1Veeam
1Veeam Backup & Replication
Jun 17, 2026
Jun 19, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user
1Veeam
1Veeam Backup & Replication
Jun 17, 2026
Mar 20, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
A vulnerability allowing remote code execution (RCE) for domain users.
1Veeam
1Backup
Jun 17, 2026
Jan 14, 2025
N/A· v4
7.2 HIGH· v3
N/A· v2
Veeam Backup for Microsoft Azure is vulnerable to Server-Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration o...Show more
Veeam Backup for Microsoft Azure is vulnerable to Server-Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.Show less
1Veeam
1Veeam Agent For Windows
Jun 17, 2026
Dec 4, 2024
N/A· v4
7.0 HIGH· v3
N/A· v2
DLL injection in Veeam Agent for Windows can occur if the system's PATH variable includes insecure locations. When the agent runs, it searches these directories for necessary DLLs. If an attacker places a malicious DLL i...Show more
DLL injection in Veeam Agent for Windows can occur if the system's PATH variable includes insecure locations. When the agent runs, it searches these directories for necessary DLLs. If an attacker places a malicious DLL in one of these directories, the Veeam Agent might load it inadvertently, allowing the attacker to execute harmful code. This could lead to unauthorized access, data theft, or disruption of servicesShow less
1Veeam
1Veeam Service Provider Console
Jun 17, 2026
Dec 4, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A vulnerability in Veeam Service Provider Console has been identified, which allows to perform arbitrary HTTP requests to arbitrary hosts of the network and get information about internal resources.