Kaseya develops remote monitoring, management, and backup software that sits at the heart of managed service provider (MSP) operations, where a single compromise can affect thousands of downstream customer environments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, creating outsized risk relative to the vendor's narrow product footprint. The exposure concentrates in flagship products such as VSA, Virtual System Administrator, and Unitrends Backup and recurs through weakness classes including improper authentication, path traversal, and SQL injection that expose administrative interfaces and backup systems to unauthorized access and data exfiltration. Defenders should treat Kaseya disclosures as supply-chain critical and prioritize patching on internet-facing instances; live exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kaseya over time
Signals from CVEs in this vendor scope (35 CVEs).
35 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-30116CRITICAL Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page where the clients for the insta | Jul 9, 2021 | 9.8 | 97 | YES | YES |
CVE-2017-12478CRITICAL It was discovered that the api/storage web interface in Unitrends Backup (UB) before 10.0.0 has an issue in which one of its input parameters was not validated. A remote attacker c | Aug 7, 2017 | 9.8 | 87 | NO | YES |
CVE-2015-6922CRITICAL Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before 9.1.0.9 does not properly require authentication, which allo | Feb 17, 2020 | 9.8 | 84 | NO | YES |
CVE-2018-20753CRITICAL Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In Ja | Feb 5, 2019 | 9.8 | 82 | YES | NO |
CVE-2018-6328CRITICAL It was discovered that the Unitrends Backup (UB) before 10.1.0 user interface was exposed to an authentication bypass, which then could allow an unauthenticated user to inject arbi | Mar 14, 2018 | 9.8 | 82 | NO | YES |
CVE-2017-12477CRITICAL It was discovered that the bpserverd proprietary protocol in Unitrends Backup (UB) before 10.0.0, as invoked through xinetd, has an issue in which its authentication can be bypasse | Aug 7, 2017 | 9.8 | 78 | NO | YES |
CVE-2021-30118CRITICAL An attacker can upload files with the privilege of the Web Server process for Kaseya VSA Unified Remote Monitoring & Management (RMM) 9.5.4.2149 and subsequently use these files to | Jul 9, 2021 | 9.8 | 75 | NO | YES |
CVE-2021-30117HIGH The API call /InstallTab/exportFldr.asp is vulnerable to a semi-authenticated boolean-based blind SQL injection in the parameter fldrId. Detailed description --- Given the followin | Jul 9, 2021 | 8.8 | 67 | NO | NO |
CVE-2021-30119MEDIUM Authenticated reflective XSS in HelpDeskTab/rcResults.asp The parameter result of /HelpDeskTab/rcResults.asp is insecurely returned in the requested web page and can be used to per | Jul 9, 2021 | 5.4 | 47 | NO | NO |
CVE-2017-12479HIGH It was discovered that an issue in the session logic in Unitrends Backup (UB) before 10.0.0 allowed using the LOGDIR environment variable during a web session to elevate an existin | Aug 7, 2017 | 8.8 | 43 | NO | YES |
Signals from CVEs in this vendor scope (35 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kaseya.
Media articles that mention a CVE ID that affects a product developed by Kaseya — matched by CVE ID, not by vendor name.