Arcserve develops a focused portfolio of backup, recovery, and unified data-protection products such as UDP, Brightstor, and D2D that operate across enterprise and midmarket environments, occupying a prominent position in the backup software landscape. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, frequently acquire public exploit tooling, and have a moderate tendency toward confirmed in-the-wild exploitation; the exposure recurs through authentication bypass, information disclosure, heap-based buffer overflows, path traversal, and cross-site scripting weaknesses characteristic of agent-based and web-facing backup infrastructure. Defenders should prioritize patches for this vendor's backup and recovery appliances, given the sensitive data and administrative trust they carry; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Arcserve over time
Signals from CVEs in this vendor scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-4068CRITICAL Directory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive information or cause a denial of service via a crafted file path t | May 29, 2015 | 9.1 | 89 | YES | NO |
CVE-2023-26258CRITICAL Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashServiceImpl leaks the AuthUUID token. This token can be used a | Jul 3, 2023 | 9.8 | 64 | NO | YES |
CVE-2020-27858HIGH This vulnerability allows remote attackers to disclose sensitive information on affected installations of CA Arcserve D2D 16.5. Authentication is not required to exploit this vulne | Jan 20, 2021 | 7.5 | 64 | NO | NO |
CVE-2024-0801HIGH A denial of service vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in ASNative.dll. | Mar 13, 2024 | 7.5 | 57 | NO | YES |
CVE-2024-0799CRITICAL An authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in the edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.server.EdgeLoginServic | Mar 13, 2024 | 9.8 | 44 | NO | YES |
CVE-2023-41998CRITICAL Arcserve UDP prior to 9.2 contained a vulnerability in the com.ca.arcflash.rps.webservice.RPSService4CPMImpl interface. A routine exists that allows an attacker to upload and execu | Nov 27, 2023 | 9.8 | 39 | NO | NO |
CVE-2025-34522CRITICAL A heap-based buffer overflow vulnerability exists in the input parsing logic of Arcserve Unified Data Protection (UDP). This flaw can be triggered without authentication by sending | Aug 27, 2025 | 9.8 | 32 | NO | NO |
CVE-2025-34523CRITICAL A heap-based buffer overflow vulnerability exists in the network-facing input handling routines of Arcserve Unified Data Protection (UDP). This flaw is reachable without authentica | Aug 27, 2025 | 9.8 | 31 | NO | NO |
CVE-2025-34520CRITICAL An authentication bypass vulnerability in Arcserve Unified Data Protection (UDP) allows unauthenticated attackers to gain unauthorized access to protected functionality or user acc | Aug 27, 2025 | 9.8 | 31 | NO | NO |
CVE-2023-41999CRITICAL An authentication bypass exists in Arcserve UDP prior to version 9.2. An unauthenticated, remote attacker can obtain a valid authentication identifier that allows them to authentic | Nov 27, 2023 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (19 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Arcserve.
Media articles that mention a CVE ID that affects a product developed by Arcserve — matched by CVE ID, not by vendor name.