Vulnerabilities in VEEAM
95 resultsCVE-2026-44963CRITICALA vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.EPSS 0.6%CVE-2024-40715HIGHA vulnerability in Veeam Backup & Replication Enterprise Manager has been identified, which allows attackers to perform authentication bypasEPSS 0.6%CVE-2026-64633CRITICALA vulnerability allowing remote unauthenticated code execution on the agent host.EPSS 0.6%CVE-2026-32998CRITICALThis vulnerability in Veeam Service Provider Console allows for remote code execution.EPSS 0.6%CVE-2024-42019CRITICALA vulnerability that allows an attacker to access the NTLM hash of the Veeam Reporter Service service account. This attack requires user intEPSS 0.5%CVE-2026-65641CRITICALA vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the service account.EPSS 0.5%CVE-2026-58072CRITICALA vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead to remotecode execuEPSS 0.5%CVE-2024-29852LOWVeeam Backup Enterprise Manager allows high-privileged users to read backup session logs.EPSS 0.5%CVE-2026-58074HIGHA vulnerability allowing a high-privileged user to execute arbitrary code on the server.EPSS 0.5%CVE-2026-21668HIGHA vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup Repository.EPSS 0.5%CVE-2024-42452HIGHA vulnerability in Veeam Backup & Replication allows a low-privileged user to start an agent remotely in server mode and obtain credentials,EPSS 0.5%CVE-2024-42023HIGHAn improper access control vulnerability allows low-privileged users to execute code with Administrator privileges remotely.EPSS 0.5%CVE-2026-32997HIGHA vulnerability allowing an authenticated user with the Backup Administrator role to write arbitrary files on Linux-based Veeam Backup & RepEPSS 0.5%CVE-2024-40718HIGHA server side request forgery vulnerability allows a low-privileged user to perform local privilege escalation through exploiting an SSRF vuEPSS 0.5%CVE-2026-58067HIGHA vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause adenial of service.EPSS 0.4%CVE-2026-58075HIGHA vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveraged toescalate privilEPSS 0.4%CVE-2026-58071HIGHA vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API asPortal AdministEPSS 0.4%CVE-2024-42457HIGHA vulnerability in Veeam Backup & Replication allows users with certain operator roles to expose saved credentials by leveraging a combinatiEPSS 0.4%CVE-2024-42020HIGHA Cross-site-scripting (XSS) vulnerability exists in the Reporter Widgets that allows HTML injection.EPSS 0.4%CVE-2026-21670HIGHA vulnerability allowing a low-privileged user to extract saved SSH credentials.EPSS 0.4%