Vulnerabilities in Veeam

89 results
Vexday analysis

O portfólio de vulnerabilidades da Veeam apresenta uma taxa de exploração ativa 3,1 vezes acima da média geral do catálogo CISA KEV, o que indica risco operacional elevado mesmo com volume total moderado de 72 CVEs. A CVE-2024-40711, atualmente a falha mais perigosa em exploração ativa, registra EPSS de 0,8819 — valor que aponta alta probabilidade de exploração em ambiente real e deve ser tratado com prioridade máxima de remediação. O tipo de falha mais recorrente é CWE-94 (injeção de código), padrão que tende a viabilizar execução remota e comprometimento profundo de sistemas de backup, categoria de ativo historicamente visada por agentes de ransomware. Com 25 CVEs críticas, 6 com PoC pública disponível e 5 surgidas nos últimos 90 dias, o cenário exige monitoramento contínuo e aplicação rigorosa de patches.

CVE-2025-23114CRITICALA vulnerability in Veeam Updater component allows Man-in-the-Middle attackers to execute arbitrary code on the affected server. This issue oEPSS 0.6%CVE-2025-59469CRITICALThis vulnerability allows a Backup or Tape Operator to write files as root.EPSS 0.6%CVE-2024-40715HIGHA vulnerability in Veeam Backup & Replication Enterprise Manager has been identified, which allows attackers to perform authentication bypasEPSS 0.6%CVE-2024-42019CRITICALA vulnerability that allows an attacker to access the NTLM hash of the Veeam Reporter Service service account. This attack requires user intEPSS 0.5%CVE-2026-65641CRITICALA vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the service account.EPSS 0.5%CVE-2024-29852LOWVeeam Backup Enterprise Manager allows high-privileged users to read backup session logs.EPSS 0.5%CVE-2026-32998CRITICALThis vulnerability in Veeam Service Provider Console allows for remote code execution.EPSS 0.5%CVE-2026-32997HIGHA vulnerability allowing an authenticated user with the Backup Administrator role to write arbitrary files on Linux-based Veeam Backup & RepEPSS 0.5%CVE-2026-21668HIGHA vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup Repository.EPSS 0.5%CVE-2024-42452HIGHA vulnerability in Veeam Backup & Replication allows a low-privileged user to start an agent remotely in server mode and obtain credentials,EPSS 0.5%CVE-2026-58072CRITICALA vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead to remotecode execuEPSS 0.5%CVE-2024-42023HIGHAn improper access control vulnerability allows low-privileged users to execute code with Administrator privileges remotely.EPSS 0.5%CVE-2024-40718HIGHA server side request forgery vulnerability allows a low-privileged user to perform local privilege escalation through exploiting an SSRF vuEPSS 0.5%CVE-2026-64633CRITICALA vulnerability allowing remote unauthenticated code execution on the agent host.EPSS 0.5%CVE-2024-42457HIGHA vulnerability in Veeam Backup & Replication allows users with certain operator roles to expose saved credentials by leveraging a combinatiEPSS 0.4%CVE-2024-42020HIGHA Cross-site-scripting (XSS) vulnerability exists in the Reporter Widgets that allows HTML injection.EPSS 0.4%CVE-2026-21670HIGHA vulnerability allowing a low-privileged user to extract saved SSH credentials.EPSS 0.4%CVE-2024-22021MEDIUMVulnerability CVE-2024-22021 allows a Veeam Recovery Orchestrator user with a low privileged role (Plan Author) to retrieve plans from a ScoEPSS 0.4%CVE-2024-42456HIGHA vulnerability in Veeam Backup & Replication platform allows a low-privileged user with a specific role to exploit a method that updates crEPSS 0.4%CVE-2026-58067HIGHA vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause adenial of service.EPSS 0.4%