Skip to content
VulniPulse

Veeam Security Advisories & CVEs

8 advisories tracked · Veeam Knowledge Base — Security Advisories · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Veeam CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your Veeam device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in Veeam's recent advisories.

Official source

Veeam Knowledge Base — Security Advisories

Polled via the official Veeam Support KB Atom feed, filtered to security advisories (KB articles mentioning CVEs or vulnerabilities). KB pages are fetched for new items to extract build numbers and fixes.

Latest Veeam advisories

Critical9.5Veeam

Critical [CVE-2026-58067 +3] Vulnerabilities Resolved in Veeam Service Provider Console 9.3

Vulnerabilities Resolved in Veeam Service Provider Console 9.3 KB ID: 4893 Product: Published: 2026-08-04 Last Modified: Veeam Software Security Commitment Veeam® is committed to ensuring its products protect customers from potential risks. As part of that commitment, we operate a Vulnerability Disclosure Program (VDP) for all Veeam products and perform extensive internal code audits. When a vulnerability is identified, our team promptly develops a patch to address and mitigate the risk. In line with our dedication to transparency, we publicly disclose the vulnerability and provide detailed mitigation information. This approach ensures that all potentially affected customers can quickly implement the necessary measures to safeguard their systems. It’s important to note that once a vulnerability and its associated patch are disclosed, attackers will likely attempt to reverse-engineer the patch to exploit unpatched deployments of Veeam software. This reality underscores the critical importance of ensuring that all customers use the latest versions of our software and install all updates and patches without delay. Issue Details A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent and obtain that agent's credentials. Severity: Critical

CVE-2026-58067CVE-2026-58071CVE-2026-58072+1
Service Provider Console
Aug 4, 2026
Critical10.0Veeam

Critical [CVE-2026-58074 +5] Vulnerabilities Resolved in Veeam ONE 13.1

Vulnerabilities Resolved in Veeam ONE 13.1 KB ID: 4892 Product: Published: 2026-07-29 Last Modified: Veeam Software Security Commitment Veeam® is committed to ensuring its products protect customers from potential risks. As part of that commitment, we operate a Vulnerability Disclosure Program (VDP) for all Veeam products and perform extensive internal code audits. When a vulnerability is identified, our team promptly develops a patch to address and mitigate the risk. In line with our dedication to transparency, we publicly disclose the vulnerability and provide detailed mitigation information. This approach ensures that all potentially affected customers can quickly implement the necessary measures to safeguard their systems. It’s important to note that once a vulnerability and its associated patch are disclosed, attackers will likely attempt to reverse-engineer the patch to exploit unpatched deployments of Veeam software. This reality underscores the critical importance of ensuring that all customers use the latest versions of our software and install all updates and patches without delay. Issue Details A vulnerability allowing remote unauthenticated code execution on the agent host. Severity: Critical CVSS v4.0 Score: 10.0CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

CVE-2026-58074CVE-2026-58075CVE-2026-64630+3
Veeam ONE
Jul 29, 2026
Critical9.4Veeam

Critical [CVE-2026-32998 +1] Vulnerability Resolved in Veeam Service Provider Console 9.2.1

Vulnerability Resolved in Veeam Service Provider Console 9.2.1 KB ID: 4853 Product: Veeam Service Provider Console | 9 | 9.1 | 9.2 Published: 2026-05-27 Last Modified: 2026-07-28 All vulnerabilities documented in this article were resolved in Veeam Service Provider Console 9.2.1.33875. Veeam Software Security Commitment Veeam® is committed to ensuring its products protect customers from potential risks. As part of that commitment, we operate a Vulnerability Disclosure Program (VDP) for all Veeam products and perform extensive internal code audits. When a vulnerability is identified, our team promptly develops a patch to address and mitigate the risk. In line with our dedication to transparency, we publicly disclose the vulnerability and provide detailed mitigation information. This approach ensures that all potentially affected customers can quickly implement the necessary measures to safeguard their systems. It’s important to note that once a vulnerability and its associated patch are disclosed, attackers will likely attempt to reverse-engineer the patch to exploit unpatched deployments of Veeam software. This reality underscores the critical importance of ensuring that all customers use the latest versions of our software and install all updates and patches without delay.

CVE-2026-32998CVE-2026-64635
Service Provider Console
Jul 28, 2026
CriticalVeeam Exploited CISA KEV

Critical [CVE-2020-14040 +33] List of Security Fixes and Improvements in Veeam Kasten for Kubernetes

List of Security Fixes and Improvements in Veeam Kasten for Kubernetes KB ID: 4825 Product: Kasten K10 by Veeam | 3 | 5 | 5.5 | 6 | 6.5 Published: 2026-03-02 Last Modified: Purpose This article aims to provide our customers' security and compliance teams with detailed information on security improvements. - Veeam Kasten for Kubernetes — Release Notes - Upgraded the Prometheus base image to resolve GHSA-hrxh-6v49-42gf - GitHub Advisory - Upgraded Dex image dependencies to resolve multiple Critical and High CVEs - Upgraded to the latest UBI base image to resolve multiple CVEs. - Updated third-party dependencies (gomplate, logger base image) in the dex and logger components to address known vulnerabilities. - Updated the UBI minimal base image to incorporate the latest security fixes. - Improved logging security for Veeam Backup & Replication API credentials and other sensitive values previously written to Kasten logs. It is recommended to upgrade Veeam Kasten and to refresh the token by manually logging out. - Upgraded components of Kasten's bundled Prometheus monitoring stack to resolve multiple CVEs - Updated base images used in the Red Hat Marketplace operator bundle to fix multiple Critical and High CVEs

CVE-2020-14040CVE-2021-23017CVE-2021-33194+31
Backup & ReplicationKasten
Jun 16, 2026
Critical9.4Veeam

Critical [CVE-2026-44963] Vulnerability Resolved in Veeam Backup & Replication 12.3.2.4854

Vulnerability Resolved in Veeam Backup & Replication 12.3.2.4854 KB ID: 4869 Product: Veeam Backup & Replication | 12 | 12.1 | 12.2 | 12.3 | 12.3.1 | 12.3.2 Published: 2026-06-09 Last Modified: 2026-06-09 All vulnerabilities documented in this article were resolved in Veeam Backup & Replication 12.3.2.4854.

CVE-2026-44963
Backup & Replication
Jun 9, 2026
Critical9.4Veeam

Critical [CVE-2026-32998] Veeam Service Provider Console: This vulnerability in Veeam Service Provider Console allows for remote code execution.

This vulnerability in Veeam Service Provider Console allows for remote code execution.

CVE-2026-32998
Service Provider Console
May 28, 2026
Critical9.9Vendor: HighVeeam

Critical [CVE-2026-21666 +5] Veeam Backup & Replication: vulnerability allowing local privilege escalation on Windows-based Veeam Backup & Replication servers.

A vulnerability allowing local privilege escalation on Windows-based Veeam Backup & Replication servers.

CVE-2026-21666CVE-2026-21667CVE-2026-21668+3
Backup & Replication
Mar 12, 2026
Critical9.9Veeam

Critical [CVE-2026-21669 +5] Veeam Backup & Replication: vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high…

A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availability (HA) deployments of Veeam Backup & Replication.

CVE-2026-21669CVE-2026-21670CVE-2026-21671+3
Backup & Replication
Mar 12, 2026

← All vendors