PatchSiren

Veeam CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Veeam CVE published 2026-08-04

CVE-2026-64634

The CVE-2026-64634 vulnerability allows for local privilege escalation to the Reporter service context. This issue has a CVSS score of 8.4, indicating a high severity level. The vulnerability was published on 2026-08-04T17:16:58.347Z and has not been modified since then. Administrators and security teams responsible for systems potentially affected by local privilege escalation vulnerabilities should be a [truncated]

CRITICAL Veeam CVE published 2026-08-04

CVE-2026-64633

CVE-2026-64633 is a critical vulnerability allowing remote unauthenticated code execution on the agent host with a CVSS score of 10. The vulnerability affects systems that require immediate attention and verification of system configurations. Administrators and security teams should verify system configurations and monitor for potential exploitation attempts. The CVE record was published on 2026-08-04T17: [truncated]

HIGH Veeam CVE published 2026-08-04

CVE-2026-58075

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T17:16:57.190Z and has not been modified since then. This vulnerability allows an unauthenticated attacker to read arbitrary files from the host, potentially leading to local privilege escalation. The CVSS score of 8.7 indicates a HIGH severity level, emphasizing the need for prompt action. Securi [truncated]

HIGH Veeam CVE published 2026-08-04

CVE-2026-58074

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T17:16:57.067Z and has not been modified since then. This vulnerability allows a high-privileged user to execute arbitrary code on the server, which can have significant operational impact. Affected operator, platform, vulnerability-management, and security-team impact should be considered when pr [truncated]

CRITICAL Veeam CVE published 2026-08-04

CVE-2026-58073

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T17:16:56.930Z and has not been modified since then. This critical vulnerability in Veeam Service Provider Console allows unauthenticated attackers to impersonate managed agents and obtain their credentials, with a CVSS score of 9.5. Organizations using Veeam Service Provider Console should priori [truncated]

CRITICAL Veeam CVE published 2026-08-04

CVE-2026-58072

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record for CVE-2026-58072 was published on 2026-08-04T17:16:56.633Z and has not been modified since then. This critical vulnerability, with a CVSS score of 9, allows arbitrary file write on the management server in Veeam Service Provider Console, potentially leading to remote code execution. Organizations using this console should [truncated]

HIGH Veeam CVE published 2026-07-22

CVE-2026-56844

A high-severity vulnerability was found in the Veeam Updater component of the Veeam Software Appliance. This vulnerability could allow a local user to elevate their privileges and gain root-level access to the underlying operating system. The CVSS score for this vulnerability is 8.4, indicating a high level of severity. The vulnerability affects the Veeam Software Appliance, and defenders should verify th [truncated]

CRITICAL Veeam CVE published 2026-06-09

CVE-2026-44963

CVE-2026-44963 is a critical vulnerability with a CVSS score of 9.4, allowing remote code execution (RCE) on a Backup Server by an authenticated domain user. The vulnerability was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-44963) and last modified on [cveModifiedAt](https://nvd.nist.gov/vuln/detail/CVE-2026-44963).

CRITICAL Veeam CVE published 2026-05-28

CVE-2026-32998

A critical remote code execution vulnerability in Veeam Service Provider Console was disclosed on May 28, 2026. The vulnerability carries a CVSS 4.0 score of 9.4, indicating severe impact potential with network attack vector, low attack complexity, and no required user interaction. The weakness has been classified as CWE-233 (Improper Handling of Parameters). Veeam has published a knowledge base article a [truncated]

HIGH Veeam CVE published 2026-05-28

CVE-2026-32997

A path traversal vulnerability in Veeam Backup & Replication allows authenticated users with the Backup Administrator role to write arbitrary files on Linux-based servers. The vulnerability stems from improper handling of absolute paths (CWE-36), enabling privileged file system manipulation. Published 2026-05-28 with CVSS 4.0 score 8.6 (HIGH). No known exploitation in the wild or ransomware campaign assoc [truncated]

HIGH Veeam CVE published 2026-05-28

CVE-2026-32996

A local privilege escalation vulnerability in Veeam Agent for Microsoft Windows was disclosed on May 28, 2026. The vulnerability is classified as CWE-532 (Insertion of Sensitive Information into Log File) and carries a CVSS 4.0 score of 7.3 (HIGH). The attack requires local access with low privileges and no user interaction, potentially allowing an attacker to gain high confidentiality, integrity, and ava [truncated]

CRITICAL Veeam CVE published 2026-03-12

CVE-2026-21708

CVE-2026-21708 is a critical remote code execution issue described as allowing a Backup Viewer to execute code as the postgres user. The supplied NVD metadata rates it 9.9/CRITICAL and lists a network-accessible, low-privilege attack with changed scope. Because the record points to Veeam advisories (KB4830 and KB4831), organizations using the affected Veeam environment should treat this as an immediate re [truncated]

HIGH Veeam CVE published 2026-03-12

CVE-2026-21672

CVE-2026-21672 is a high-severity local privilege escalation issue affecting Windows-based Veeam Backup & Replication servers. The supplied NVD data rates it 8.8 (HIGH) and points to vendor KB references for remediation guidance. Because the attack requires local access and low privileges, the main risk is post-compromise escalation on systems already reachable by an attacker or untrusted user.

CRITICAL Veeam CVE published 2026-03-12

CVE-2026-21671

CVE-2026-21671 is a critical remote code execution issue in Veeam Backup & Replication high availability (HA) deployments. According to the supplied NVD record, an authenticated user with the Backup Administrator role can trigger RCE, and the issue is rated CVSS 9.1.

HIGH Veeam CVE published 2026-03-12

CVE-2026-21670

CVE-2026-21670 is a high-severity Veeam issue that can let a low-privileged user extract saved SSH credentials. NVD maps the affected product to Veeam Backup & Replication and lists the vulnerable version range as 13.0.0.496 through 13.0.1.1071. Because the flaw exposes credentials, the main risk is unauthorized access to systems reachable with those SSH keys or passwords, especially where stored credenti [truncated]

CRITICAL Veeam CVE published 2026-03-12

CVE-2026-21669

CVE-2026-21669 is a critical remote code execution issue affecting Veeam Backup & Replication on the Backup Server. According to the NVD record, the vulnerable range includes versions 13.0.0.496 through before 13.0.1.2067, and the issue can be reached by an authenticated domain user. The CVSS vector indicates network attackability, low attack complexity, required low privileges, no user interaction, and h [truncated]

HIGH Veeam CVE published 2026-03-12

CVE-2026-21668

CVE-2026-21668 is a high-severity issue in Veeam Backup & Replication where an authenticated domain user may bypass restrictions and manipulate arbitrary files on a Backup Repository. NVD lists affected versions from 12.0.0.1402 through 12.3.2.4465. The vendor advisory referenced by NVD is available at Veeam KB4830.

Known exploited Veeam CVE published 2024-10-17

CVE-2024-40711

CVE-2024-40711 is a deserialization vulnerability in Veeam Backup & Replication that CISA added to its Known Exploited Vulnerabilities catalog on 2024-10-17. CISA also marks it as having known ransomware campaign use. Because it is a KEV-listed issue, defenders should treat it as urgent and follow vendor mitigation guidance immediately, or discontinue use if mitigations are not available.

Known exploited Veeam CVE published 2023-08-22

CVE-2023-27532

CVE-2023-27532 is a CISA Known Exploited Vulnerability affecting Veeam Backup & Replication Cloud Connect. CISA added it to the KEV catalog on 2023-08-22, marked it as known ransomware campaign use, and set a due date of 2023-09-12 for required action.

Known exploited Veeam CVE published 2022-12-13

CVE-2022-26501

CVE-2022-26501 is a Veeam Backup & Replication remote code execution vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2022-12-13. CISA also marked it as having known ransomware campaign use. In practice, that means organizations running Veeam Backup & Replication should treat this as a high-priority remediation item and follow vendor update guidance as soon as possible.

Known exploited Veeam CVE published 2022-12-13

CVE-2022-26500

CVE-2022-26500 is a remote code execution vulnerability in Veeam Backup & Replication that CISA added to the Known Exploited Vulnerabilities catalog on 2022-12-13. CISA also marks it as having known ransomware campaign use, which makes prompt patching and validation especially important. The supplied corpus does not include exploit mechanics or affected-version details, so the safest action is to follow v [truncated]