Skip to content
VulniPulse

Veeam Backup & Replication Vulnerabilities & Security Advisories

13 advisories tracked · Veeam Knowledge Base — Security Advisories · 2 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Veeam advisory that VulniPulse classified as Backup & Replication, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 5 critical, 4 high, 1 medium.

Android app · Google Play

Monitor Veeam CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Veeam Knowledge Base — Security Advisories

Polled via the official Veeam Support KB Atom feed, filtered to security advisories (KB articles mentioning CVEs or vulnerabilities). KB pages are fetched for new items to extract build numbers and fixes.

Latest Veeam Backup & Replication advisories

Critical9.4Veeam Updated

Critical [CVE-2025-64392 +2] Vulnerabilities Resolved in Veeam Backup & Replication 12.3.2 P4

Vulnerabilities Resolved in Veeam Backup & Replication 12.3.2 P4 KB ID: 4934 Product: Published: 2026-10-06 Last Modified: Article Applicability All vulnerabilities listed in this article: - Affect only Veeam Backup & Replication 12.3.2 P3 (build 12.3.2.4854) and older builds. - Do not affect any Veeam Backup & Replication version 13 builds. Customers are reminded that Veeam Backup & Replication version 12 will reach End of Support on 2027-02-28. Veeam Software Security Commitment Veeam® is committed to ensuring its products protect customers from potential risks. As part of that commitment, we operate a Vulnerability Disclosure Program (VDP) for all Veeam products and perform extensive internal code audits. When a vulnerability is identified, our team promptly develops a patch to address and mitigate the risk. In line with our dedication to transparency, we publicly disclose the vulnerability and provide detailed mitigation information. This approach ensures that all potentially affected customers can quickly implement the necessary measures to safeguard their systems. It’s important to note that once a vulnerability and its associated patch are disclosed, attackers will likely attempt to reverse-engineer the patch to exploit unpatched deployments of Veeam software.

CVE-2025-64392CVE-2025-64393CVE-2026-93026
Backup & Replication
Oct 6, 2026
Medium6.8Veeam Updated

Medium [CVE-2026-58070 +3] Vulnerabilities Resolved in Veeam Backup & Replication 13.1

Vulnerabilities Resolved in Veeam Backup & Replication 13.1 KB ID: 4902 Product: Published: 2026-08-25 Last Modified: Veeam Software Security Commitment Veeam® is committed to ensuring its products protect customers from potential risks. As part of that commitment, we operate a Vulnerability Disclosure Program (VDP) for all Veeam products and perform extensive internal code audits. When a vulnerability is identified, our team promptly develops a patch to address and mitigate the risk. In line with our dedication to transparency, we publicly disclose the vulnerability and provide detailed mitigation information. This approach ensures that all potentially affected customers can quickly implement the necessary measures to safeguard their systems. It’s important to note that once a vulnerability and its associated patch are disclosed, attackers will likely attempt to reverse-engineer the patch to exploit unpatched deployments of Veeam software. This reality underscores the critical importance of ensuring that all customers use the latest versions of our software and install all updates and patches without delay. Issue Details A vulnerability that causes guest OS credentials used for Application Aware processing to be recorded in cleartext in logs on the guest machine. Severity: Medium CVSS v4.0 Score: 6.8CVSS: AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

CVE-2026-58070CVE-2025-64391CVE-2026-58068+1
Backup & Replication
Aug 25, 2026
UnratedVeeam Exploited CISA KEV Updated

Advisory [CVE-2021-35971 +48] List of Security Fixes and Improvements in Veeam Backup & Replication

List of Security Fixes and Improvements in Veeam Backup & Replication KB ID: 3103 Product: Published: 2020-03-02 Last Modified: 2026-10-05 Purpose 13.1.0.411 - System. Security. Cryptography. Xml upgraded to version 10.0.7 - Microsoft. AspNetCore. DataProtection upgraded to version 10.0.7 - CoreWCF.Primitives upgraded to version 1.8.1 - MailKit upgraded to version 4.17.0 - MimeKit upgraded to version 4.17.0 - OpenTelemetry upgraded to version 1.15.3 - SQLite upgraded to version 3.53.2 - @angular/core upgraded to version 21.2.17 - OpenSSL upgraded to version 3.5.7 - curl upgraded to version 8.21.0 - zlib upgraded to version 1.3.2 - libarchive upgraded to version 3.8.5 13.0.3.63 - dompurify upgraded to version 3.4.12 13.0.2.29 - uuid upgraded to version 14.0.0 - Snappier upgraded to version 1.3.1 - picomatch upgraded to version 2.3.2 - Microsoft. Kiota. Abstractions upgraded to version 1.22.0 - lodash upgraded to version 4.18.1 - AutoMapper replaced with MagicMapper 14.0.1 13.0.1.2067 13.0.1.1071 - CVE-2025-55125 vulnerability was fixed. 13.0.1.180 - Microsoft. IdentityModel. JsonWebTokens upgraded to version 8.12.0 13.0.0.4967 - Communication protocol was switched to gRPC - Libxml2 upgraded to version 2.13.8 - Newtonsoft. Json upgraded to version 13.0.1 - RestSharp upgraded to version 112.1.0 - Microsoft. Extensions. Caching. Memory upgraded to version 8.0.1

CVE-2021-35971CVE-2022-26500CVE-2022-26501+46
Backup & Replication
Aug 25, 2026
UnratedVeeam Updated

Advisory [CVE-2022-26503 +7] List of Security Fixes and Improvements in Veeam Agent for Microsoft Windows

List of Security Fixes and Improvements in Veeam Agent for Microsoft Windows KB ID: 3108 Product: Published: 2020-03-02 Last Modified: 2026-10-05 Purpose 13.1.0.544 - CVE-2025-64391 vulnerability was fixed. - MessagePack upgraded to version 2.5.302 - OpenSSL upgraded to version 3.5.7 13.0.4.1341 - SQLite upgraded to version 3.53.2 13.0.3.1220 - Microsoft. Kiota. Abstractions upgraded to version 1.22.0 13.0.1.120 13.0.0.835 - Communication protocol was switched to gRPC - System. IdentityModel. Tokens. Jwt upgraded to version 8.0.2 6.3.2.1302 6.3.2.1205 6.3.0.177 - Vulnerability ( CVE-2024-45207 ) in Veeam Agent for Microsoft Windows was fixed. 6.1.2.134 6.1.0.349 - OpenSSL library updated to 1.0.2zi. - LZ4 library updated to 1.9.4. - Stronger backup encryption. - (See pg. 7 of Veeam Backup & Replication 12.1 What's New PDF ) 6.0.2.1090 6.0.0.960 - Added support for networks with NTLM authentication disabled ( Kerberos-only authentication ). - Audit capabilities were improved. - zlib has been updated to version 1.2.13. 5.0.3.5029 - liblz4 was updated to v1.9.4. - zlib was updated to v1.2.13. - PuTTY was updated to 0.80. 5.0.3.4708 5.0.0.4301 4.0.2.2208 4.0.0.1811 - A custom security descriptor was provided for the driver's control device (vulnerability reported by Mile Karry).

CVE-2022-26503CVE-2024-29853CVE-2024-45207+5
Backup & ReplicationAgents
Aug 25, 2026
UnratedVeeam

Advisory [CVE-2024-40709] List of Security Fixes and Improvements in Veeam Agent for Linux

List of Security Fixes and Improvements in Veeam Agent for Linux KB ID: 3109 Product: Published: 2020-03-02 Last Modified: 2026-08-21 Purpose 13.1.0.252 - OpenSSL upgraded to version 3.5.7 13.0.1.404 - The port range opened on the host firewall was changed to 2500-3300. 13.0.3.213 13.0.1.94 13.0.0.0.772 6.3.2.1307 6.2.0.101 - CVE-2024-40709 vulnerability was fixed. 6.1.0.1498 - OpenSSL library updated to 1.0.2zi. - LZ4 library updated to 1.9.4. - Updated zlib library to 1.2.13. - Stronger backup encryption. - (See pg. 7 of Veeam Backup & Replication 12.1 What's New PDF ) 6.0.2.1168 5.0.2.4707 - liblz4 was updated to v1.9.4. - zlib was updated to v1.2.13. - PuTTY was updated to 0.80. 5.0.0.4318 - Addressed an issue with insecure default permissions of files created in /tmp 4.0.1.2365 - Sensitive information used by managed Linux agent may get logged in the Linux operating system logs. - Creating an SMB repository using CLI command causes plain text password to be logged in the Veeam debug log. 4.0.0.1961 - An issue of insecure file permissions was addressed (vulnerability reported by RACK911 Labs). - OpenSSL was updated to version 1.0.2t. As we're establishing this new process, we appreciate any feedback on the content or format of this KB article. Please let us know in the corresponding topic on the Veeam Community Forums.

CVE-2024-40709
Backup & ReplicationAgents
Aug 25, 2026
High8.4Veeam

High [CVE-2026-56844] Backup and Replication: vulnerability in the Veeam Updater component of the Veeam Software Appliance that could

A vulnerability in the Veeam Updater component of the Veeam Software Appliance that could allow a local user to elevate their privileges and gain root-level access to the underlying operating system. Affected product named by the advisory: Backup and Replication.

CVE-2026-56844
Backup & Replication
Jul 22, 2026
High8.4Veeam

High Veeam Software Appliance/Veeam Infrastructure Appliance — Updater Component Vulnerability

Veeam Software Appliance/Veeam Infrastructure Appliance — Updater Component Vulnerability KB ID: 4879 Product: Veeam Backup & Replication | 13 Published: 2026-07-14 Last Modified: 2026-07-14 Veeam Software Security Commitment Veeam® is committed to ensuring its products protect customers from potential risks. As part of that commitment, we operate a Vulnerability Disclosure Program (VDP) for all Veeam products and perform extensive internal code audits. When a vulnerability is identified, our team promptly develops a patch to address and mitigate the risk. In line with our dedication to transparency, we publicly disclose the vulnerability and provide detailed mitigation information. This approach ensures that all potentially affected customers can quickly implement the necessary measures to safeguard their systems. It’s important to note that once a vulnerability and its associated patch are disclosed, attackers will likely attempt to reverse-engineer the patch to exploit unpatched deployments of Veeam software. This reality underscores the critical importance of ensuring that all customers use the latest versions of our software and install all updates and patches without delay. Vulnerability Details A vulnerability in the Veeam Updater component allows a local user to elevate their privileges and gain root-level access to the underlying operating system.

Backup & Replication
Jul 14, 2026
CriticalVeeam Exploited CISA KEV Updated

Critical [CVE-2020-14040 +67] List of Security Fixes and Improvements in Veeam Kasten for Kubernetes

List of Security Fixes and Improvements in Veeam Kasten for Kubernetes KB ID: 4825 Product: Kasten K10 by Veeam | 3 | 5 | 5.5 | 6 | 6.5 Published: 2026-03-02 Last Modified: Purpose This article aims to provide our customers' security and compliance teams with detailed information on security improvements. - Veeam Kasten for Kubernetes — Release Notes - Also resolves 8 Medium severity CVEs in the same and other packages. - Upgraded to latest UBI base image to resolve multiple CVEs in base OS packages. - Updated the Go runtime to resolve additional upstream Go CVEs. - Updated the bundled Prometheus Helm chart to resolve security issues. - Upgraded the Prometheus base image to resolve GHSA-hrxh-6v49-42gf - GitHub Advisory - Upgraded Dex image dependencies to resolve multiple Critical and High CVEs - Updated third-party dependencies (gomplate, logger base image) in the dex and logger components to address known vulnerabilities. - Updated the UBI minimal base image to incorporate the latest security fixes. - Improved logging security for Veeam Backup & Replication API credentials and other sensitive values previously written to Kasten logs. It is recommended to upgrade Veeam Kasten and to refresh the token by manually logging out. - Upgraded components of Kasten's bundled Prometheus monitoring stack to resolve multiple CVEs

CVE-2020-14040CVE-2021-23017CVE-2021-33194+65
Backup & ReplicationKasten
Jun 16, 2026
Critical9.4Veeam

Critical [CVE-2026-44963] Vulnerability Resolved in Veeam Backup & Replication 12.3.2.4854

Vulnerability Resolved in Veeam Backup & Replication 12.3.2.4854 KB ID: 4869 Product: Veeam Backup & Replication | 12 | 12.1 | 12.2 | 12.3 | 12.3.1 | 12.3.2 Published: 2026-06-09 Last Modified: 2026-06-09 All vulnerabilities documented in this article were resolved in Veeam Backup & Replication 12.3.2.4854.

CVE-2026-44963
Backup & Replication
Jun 9, 2026
High7.3Veeam

High [CVE-2026-32996 +1] Veeam Backup & Replication: vulnerability allowing an authenticated user with the Backup Administrator role to write arbitrary files on Linux-based Veeam…

A vulnerability allowing an authenticated user with the Backup Administrator role to write arbitrary files on Linux-based Veeam Backup & Replication server.

CVE-2026-32996CVE-2026-32997
Backup & Replication
May 28, 2026
High7.3Veeam

High [CVE-2026-32996 +1] Veeam Agent: This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.

This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation. Affected product named by the advisory: Backup and Replication.

CVE-2026-32996CVE-2026-32997
Backup & Replication
May 28, 2026
Critical9.9Vendor: HighVeeam

Critical [CVE-2026-21666 +5] Veeam Backup & Replication: vulnerability allowing local privilege escalation on Windows-based Veeam Backup & Replication servers.

A vulnerability allowing local privilege escalation on Windows-based Veeam Backup & Replication servers.

CVE-2026-21666CVE-2026-21667CVE-2026-21668+3
Backup & Replication
Mar 12, 2026
Critical9.9Veeam

Critical [CVE-2026-21669 +5] Veeam Backup & Replication: vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high…

A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availability (HA) deployments of Veeam Backup & Replication.

CVE-2026-21669CVE-2026-21670CVE-2026-21671+3
Backup & Replication
Mar 12, 2026

← All Veeam advisories