Vulnerabilities (CVE)

Filtered by vendor Veeam Subscribe
Total 71 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-21708 1 Veeam 1 Veeam Backup \& Replication 2026-06-17 N/A 9.9 CRITICAL
A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user.
CVE-2026-21671 1 Veeam 1 Veeam Backup \& Replication 2026-06-17 N/A 9.1 CRITICAL
A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availability (HA) deployments of Veeam Backup & Replication.
CVE-2026-21670 1 Veeam 1 Veeam Backup \& Replication 2026-06-17 N/A 7.7 HIGH
A vulnerability allowing a low-privileged user to extract saved SSH credentials.
CVE-2026-21669 1 Veeam 1 Veeam Backup \& Replication 2026-06-17 N/A 9.9 CRITICAL
A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.
CVE-2026-21668 1 Veeam 1 Veeam Backup \& Replication 2026-06-17 N/A 8.8 HIGH
A vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup Repository.
CVE-2026-21667 1 Veeam 1 Veeam Backup \& Replication 2026-06-17 N/A 9.9 CRITICAL
A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.
CVE-2026-21666 1 Veeam 1 Veeam Backup \& Replication 2026-06-17 N/A 9.9 CRITICAL
A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.
CVE-2025-59470 1 Veeam 1 Veeam Backup \& Replication 2026-06-17 N/A 9.0 CRITICAL
This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter.
CVE-2025-59469 1 Veeam 1 Veeam Backup \& Replication 2026-06-17 N/A 9.0 CRITICAL
This vulnerability allows a Backup or Tape Operator to write files as root.
CVE-2025-59468 1 Veeam 1 Veeam Backup \& Replication 2026-06-17 N/A 9.0 CRITICAL
This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending a malicious password parameter.
CVE-2025-55125 1 Veeam 1 Veeam Backup \& Replication 2026-06-17 N/A 7.8 HIGH
This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious backup configuration file.
CVE-2025-48984 1 Veeam 1 Veeam Backup \& Replication 2026-06-17 N/A 8.8 HIGH
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.
CVE-2025-48983 1 Veeam 1 Veeam Backup \& Replication 2026-06-17 N/A 9.9 CRITICAL
A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructure hosts by an authenticated domain user.
CVE-2025-48982 1 Veeam 1 Veeam Agent For Windows 2026-06-17 N/A 7.8 HIGH
This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation if a system administrator is tricked into restoring a malicious file.
CVE-2025-24286 1 Veeam 1 Veeam Backup \& Replication 2026-06-17 N/A 7.2 HIGH
A vulnerability allowing an authenticated user with the Backup Operator role to modify backup jobs, which could execute arbitrary code.
CVE-2025-23121 1 Veeam 1 Veeam Backup \& Replication 2026-06-17 N/A 8.8 HIGH
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user
CVE-2025-23120 1 Veeam 1 Veeam Backup \& Replication 2026-06-17 N/A 8.8 HIGH
A vulnerability allowing remote code execution (RCE) for domain users.
CVE-2025-23082 1 Veeam 1 Backup 2026-06-17 N/A 7.2 HIGH
Veeam Backup for Microsoft Azure is vulnerable to Server-Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
CVE-2024-45207 1 Veeam 1 Veeam Agent For Windows 2026-06-17 N/A 7.0 HIGH
DLL injection in Veeam Agent for Windows can occur if the system's PATH variable includes insecure locations. When the agent runs, it searches these directories for necessary DLLs. If an attacker places a malicious DLL in one of these directories, the Veeam Agent might load it inadvertently, allowing the attacker to execute harmful code. This could lead to unauthorized access, data theft, or disruption of services
CVE-2024-45206 1 Veeam 1 Veeam Service Provider Console 2026-06-17 N/A 6.5 MEDIUM
A vulnerability in Veeam Service Provider Console has been identified, which allows to perform arbitrary HTTP requests to arbitrary hosts of the network and get information about internal resources.