20 Total CVEs
20 AI Analyzed
0 CISA KEV
7 Critical

Profile

0% ended up actively exploited 0 of 20 added to CISA KEV
35% rated critical (CVSS 9.0+) 7 critical, 13 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

20 CVEs in the last 12 months

Products

  • ONE6
  • Backup & Replication4
  • Service Provider Console2
  • Backup2
  • Affected Software1

5 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-20 of 20 CVEs
CVE-2026-64634
Analyzed
8.4
Veeam ONE

A vulnerability allowing local privilege escalation to the Reporter service context

2026-08-05
CVE-2026-64633
Analyzed
10
Veeam ONE

A critical code injection vulnerability in Veeam ONE allows remote unauthenticated attackers to execute arbitrary code on the agent host.

2026-08-05
CVE-2026-64632
Analyzed
8.5
Veeam ONE

A vulnerability allowing a low-privileged user to capture the NTLM credentials of the Reporter service account

2026-08-27
CVE-2026-64631
Analyzed
8.6
Veeam ONE

A vulnerability allowing a low-privileged user to inject SQL and extract database contents

2026-08-05
CVE-2026-58075
Analyzed
8.7
Veeam ONE

A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveraged toescalate privileges local...

2026-08-05
CVE-2026-58074
Analyzed
8.6
Veeam ONE

A vulnerability allowing a high-privileged user to execute arbitrary code on the server

2026-08-05
CVE-2026-58071
Analyzed
8.2
Veeam Service Provider Console

A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API asPortal Administrator duri...

2026-08-05
CVE-2026-58067
Analyzed
8.7
Veeam Service Provider Console

A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause adenial of service

2026-08-05
CVE-2026-21708
Analyzed
9.9
Veeam Backup & Replication

A vulnerability allows a user with Backup Viewer privileges to perform remote code execution as the postgres user on the backup system.

2026-03-13
CVE-2026-21672
Analyzed
8.8
Veeam Backup

A vulnerability allowing local privilege escalation on Windows-based Veeam Backup & Replication servers

2026-03-13
CVE-2026-21671
Analyzed
9.1
Veeam Backup

An authenticated user with the Backup Administrator role can perform remote code execution in high availability deployments of Veeam Backup & Replicat...

2026-03-13
CVE-2026-21670
Analyzed
7.7
Veeam Affected Software

A vulnerability allowing a low-privileged user to extract saved SSH credentials

2026-03-14
CVE-2026-21669
Analyzed
9.9
Veeam Backup & Replication

An authenticated domain user can execute arbitrary code on the Backup Server, leading to a complete compromise of the backup system.

2026-03-13
CVE-2026-21668
Analyzed
8.8
Veeam Multiple Products

A vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup Repository

2026-03-13
CVE-2026-21667
Analyzed
9.9
Veeam Backup & Replication

A vulnerability in the Backup Server allows an authenticated domain user to perform remote code execution, compromising the backup environment.

2026-03-13
CVE-2026-21666
Analyzed
9.9
Veeam Backup & Replication

An authenticated domain user can achieve remote code execution on the Backup Server, leading to full system compromise.

2026-03-13
CVE-2025-55125
Analyzed
7.8
Veeam Multiple Products

This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious backup configuration file

2026-01-09
CVE-2025-48984
Analyzed
8.8
Veeam Multiple Products

A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user

2025-10-31
CVE-2025-48983
Analyzed
9.9
Veeam Multiple Products

A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructure hosts by...

2025-10-31
CVE-2025-48982
Analyzed
7.3
Veeam Multiple Products

This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation if a system administrator is tricked into restoring a ma...

2025-10-31