Unknown [CVE-2021-35971 +44] List of Security Fixes and Improvements in Veeam Backup & Replication
This security Veeam advisory covers CVE-2021-35971 and CVE-2022-26500 and 43 more CVEs.
Android app · Google Play
Monitor future Veeam CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
List of Security Fixes and Improvements in Veeam Backup & Replication
KB ID: 3103
Product:
Published: 2020-03-02
Last Modified: 2026-08-21
Purpose
13.1.0.411
- System. Security. Cryptography. Xml upgraded to version 10.0.7
- Microsoft. AspNetCore. DataProtection upgraded to version 10.0.7
- CoreWCF.Primitives upgraded to version 1.8.1
- MailKit upgraded to version 4.17.0
- MimeKit upgraded to version 4.17.0
- OpenTelemetry upgraded to version 1.15.3
- SQLite upgraded to version 3.53.2
- @angular/core upgraded to version 21.2.17
- OpenSSL upgraded to version 3.5.7
- curl upgraded to version 8.21.0
- zlib upgraded to version 1.3.2
- libarchive upgraded to version 3.8.5
13.0.3.63
- dompurify upgraded to version 3.4.12
13.0.2.29
- uuid upgraded to version 14.0.0
- Snappier upgraded to version 1.3.1
- picomatch upgraded to version 2.3.2
- Microsoft. Kiota. Abstractions upgraded to version 1.22.0
- lodash upgraded to version 4.18.1
- AutoMapper replaced with MagicMapper 14.0.1
13.0.1.2067
13.0.1.1071
- CVE-2025-55125 vulnerability was fixed.
13.0.1.180
- Microsoft. IdentityModel. JsonWebTokens upgraded to version 8.12.0
13.0.0.4967
- Communication protocol was switched to gRPC
- Libxml2 upgraded to version 2.13.8
- Newtonsoft. Json upgraded to version 13.0.1
- RestSharp upgraded to version 112.1.0
- Microsoft. Extensions. Caching. Memory upgraded to version 8.0.1
CISA Known Exploited Vulnerability
- Listed:
- Dec 13, 2022 · federal remediation due Jan 3, 2023
- Required action:
- Apply updates per vendor instructions.
- Ransomware use:
- Known
KEV is a prioritization signal from CISA — remediation detail still comes from the vendor advisory.
Affected versions
No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.
Official advisory · medium-confidence parse· fetched 44 minutes ago·verify at source
Fixed versions
No fixed release is recorded yet. That does not prove no patch exists — confirm against the vendor advisory.
Official advisory · medium-confidence parse· fetched 44 minutes ago·verify at source
Mitigation checklist
- List of Security Fixes and Improvements in Veeam Backup & Replication KB ID: 3103 Product: Veeam Backup & Replication | 10 | 11 | 12 | 12.1 | 12.2 | 12.3 | 12.3.1 | 12.3.2 | 13 | 13.1 Published: 2020-03-02 Last Modified: 2026-08-21 Purpose This article describes all security-related fixes and improvements introduced in each release or update of Veeam Backup & Replication.
- The goal of this article is to provide our customers' security and compliance teams with detailed information on security improvements between releases, in order to help them make an informed decision on whether it is critical to upgrade from their current Veeam Backup & Replication version to a latter one.
- Added possibility to limit the number of logon sessions per user and to log off users after an inactivity period SMTP certificates validation was added for email notifications Network communication between CDP components is encrypted with TLS Disabled insecure TLS protocols in communication with VMware infrastructure zlib has been updated to version 1.2.13 OpenSSL version has been updated to 1.0.2ze Putty has been updated to version 0.76 11.0.1.1261 P20240304 VMware Virtual Disk Development Kit (VDDK) was updated to 7.0.3.4.
Official advisory · medium-confidence parse· fetched 44 minutes ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.