Skip to content
VulniPulse

Veeam Backup & Replication Vulnerabilities & Security Advisories

13 advisories tracked · Veeam Knowledge Base — Security Advisories · 2 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Veeam advisory that VulniPulse classified as Backup & Replication, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 5 critical, 4 high, 1 medium.

Android app · Google Play

Monitor Veeam CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Veeam Knowledge Base — Security Advisories

Polled via the official Veeam Support KB Atom feed, filtered to security advisories (KB articles mentioning CVEs or vulnerabilities). KB pages are fetched for new items to extract build numbers and fixes.

Latest Veeam Backup & Replication advisories

Critical9.4Veeam Updated

Critical [CVE-2025-64392 +2] Vulnerabilities Resolved in Veeam Backup & Replication 12.3.2 P4

Vulnerabilities Resolved in Veeam Backup & Replication 12.3.2 P4 KB ID: 4934 Product: Published: 2026-10-06 Last Modified: Article Applicability All vulnerabilities listed in this article: - Affect only Veeam Backup & Replication 12.3.2 P3 (build 12.3.2.4854) and older builds. - Do not affect any Veeam Backup & Replication version 13 builds. Customers are reminded that Veeam Backup & Replication version 12 will reach End of Support on 2027-02-28. Veeam Software Security Commitment Veeam® is committed to ensuring its products protect customers from potential risks. As part of that commitment, we operate a Vulnerability Disclosure Program (VDP) for all Veeam products and perform extensive internal code audits. When a vulnerability is identified, our team promptly develops a patch to address and mitigate the risk. In line with our dedication to transparency, we publicly disclose the vulnerability and provide detailed mitigation information. This approach ensures that all potentially affected customers can quickly implement the necessary measures to safeguard their systems. It’s important to note that once a vulnerability and its associated patch are disclosed, attackers will likely attempt to reverse-engineer the patch to exploit unpatched deployments of Veeam software.

CVE-2025-64392CVE-2025-64393CVE-2026-93026
Backup & Replication
Oct 6, 2026
CriticalVeeam Exploited CISA KEV Updated

Critical [CVE-2020-14040 +67] List of Security Fixes and Improvements in Veeam Kasten for Kubernetes

List of Security Fixes and Improvements in Veeam Kasten for Kubernetes KB ID: 4825 Product: Kasten K10 by Veeam | 3 | 5 | 5.5 | 6 | 6.5 Published: 2026-03-02 Last Modified: Purpose This article aims to provide our customers' security and compliance teams with detailed information on security improvements. - Veeam Kasten for Kubernetes — Release Notes - Also resolves 8 Medium severity CVEs in the same and other packages. - Upgraded to latest UBI base image to resolve multiple CVEs in base OS packages. - Updated the Go runtime to resolve additional upstream Go CVEs. - Updated the bundled Prometheus Helm chart to resolve security issues. - Upgraded the Prometheus base image to resolve GHSA-hrxh-6v49-42gf - GitHub Advisory - Upgraded Dex image dependencies to resolve multiple Critical and High CVEs - Updated third-party dependencies (gomplate, logger base image) in the dex and logger components to address known vulnerabilities. - Updated the UBI minimal base image to incorporate the latest security fixes. - Improved logging security for Veeam Backup & Replication API credentials and other sensitive values previously written to Kasten logs. It is recommended to upgrade Veeam Kasten and to refresh the token by manually logging out. - Upgraded components of Kasten's bundled Prometheus monitoring stack to resolve multiple CVEs

CVE-2020-14040CVE-2021-23017CVE-2021-33194+65
Backup & ReplicationKasten
Jun 16, 2026
Critical9.4Veeam

Critical [CVE-2026-44963] Vulnerability Resolved in Veeam Backup & Replication 12.3.2.4854

Vulnerability Resolved in Veeam Backup & Replication 12.3.2.4854 KB ID: 4869 Product: Veeam Backup & Replication | 12 | 12.1 | 12.2 | 12.3 | 12.3.1 | 12.3.2 Published: 2026-06-09 Last Modified: 2026-06-09 All vulnerabilities documented in this article were resolved in Veeam Backup & Replication 12.3.2.4854.

CVE-2026-44963
Backup & Replication
Jun 9, 2026
Critical9.9Vendor: HighVeeam

Critical [CVE-2026-21666 +5] Veeam Backup & Replication: vulnerability allowing local privilege escalation on Windows-based Veeam Backup & Replication servers.

A vulnerability allowing local privilege escalation on Windows-based Veeam Backup & Replication servers.

CVE-2026-21666CVE-2026-21667CVE-2026-21668+3
Backup & Replication
Mar 12, 2026
Critical9.9Veeam

Critical [CVE-2026-21669 +5] Veeam Backup & Replication: vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high…

A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availability (HA) deployments of Veeam Backup & Replication.

CVE-2026-21669CVE-2026-21670CVE-2026-21671+3
Backup & Replication
Mar 12, 2026

← All Veeam advisories