Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Kaseya

First CVE: Jul 14, 2014Active for: 12 yearsTotal CVEs: 35
76.9
VTI Score
TOP TARGET

Kaseya develops remote monitoring, management, and backup software that sits at the heart of managed service provider (MSP) operations, where a single compromise can affect thousands of downstream customer environments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, creating outsized risk relative to the vendor's narrow product footprint. The exposure concentrates in flagship products such as VSA, Virtual System Administrator, and Unitrends Backup and recurs through weakness classes including improper authentication, path traversal, and SQL injection that expose administrative interfaces and backup systems to unauthorized access and data exfiltration. Defenders should treat Kaseya disclosures as supply-chain critical and prioritize patching on internet-facing instances; live exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
35
Total CVEs
More Total CVEs than 98% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
8.1
Avg CVSS Score
Higher Avg CVSS Score than 80% of tracked vendors
5.7%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Kaseya over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 14, 2014
12 years ago
Most Recent CVE
Apr 15, 2022
1,561 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (35 CVEs).

35 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-30116CRITICAL
Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page where the clients for the insta
Jul 9, 20219.897YESYES
CVE-2017-12478CRITICAL
It was discovered that the api/storage web interface in Unitrends Backup (UB) before 10.0.0 has an issue in which one of its input parameters was not validated. A remote attacker c
Aug 7, 20179.887NOYES
CVE-2015-6922CRITICAL
Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before 9.1.0.9 does not properly require authentication, which allo
Feb 17, 20209.884NOYES
CVE-2018-20753CRITICAL
Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In Ja
Feb 5, 20199.882YESNO
CVE-2018-6328CRITICAL
It was discovered that the Unitrends Backup (UB) before 10.1.0 user interface was exposed to an authentication bypass, which then could allow an unauthenticated user to inject arbi
Mar 14, 20189.882NOYES
CVE-2017-12477CRITICAL
It was discovered that the bpserverd proprietary protocol in Unitrends Backup (UB) before 10.0.0, as invoked through xinetd, has an issue in which its authentication can be bypasse
Aug 7, 20179.878NOYES
CVE-2021-30118CRITICAL
An attacker can upload files with the privilege of the Web Server process for Kaseya VSA Unified Remote Monitoring & Management (RMM) 9.5.4.2149 and subsequently use these files to
Jul 9, 20219.875NOYES
CVE-2021-30117HIGH
The API call /InstallTab/exportFldr.asp is vulnerable to a semi-authenticated boolean-based blind SQL injection in the parameter fldrId. Detailed description --- Given the followin
Jul 9, 20218.867NONO
CVE-2021-30119MEDIUM
Authenticated reflective XSS in HelpDeskTab/rcResults.asp The parameter result of /HelpDeskTab/rcResults.asp is insecurely returned in the requested web page and can be used to per
Jul 9, 20215.447NONO
CVE-2017-12479HIGH
It was discovered that an issue in the session logic in Unitrends Backup (UB) before 10.0.0 allowed using the LOGDIR environment variable during a web session to elevate an existin
Aug 7, 20178.843NOYES
View all 35 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products35 CVEs
20%
40%
37%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local4 (11.4%)
Network28 (80.0%)
Unknown3 (8.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low31 (88.6%)
High1 (2.9%)
Unknown3 (8.6%)
User Interaction
None30 (85.7%)
Unknown3 (8.6%)
Required2 (5.7%)
Privileges Required
Low12 (34.3%)
High1 (2.9%)
None19 (54.3%)
Unknown3 (8.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (35 CVEs).

CISA KEV
2 CVEs
5.7% of CVEs· 100th percentile
Metasploit
4 CVEs
11.4% of CVEs· 98th percentile
Nuclei
3 CVEs
8.6% of CVEs· 96th percentile
ExploitDB
8 CVEs
22.9% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Kaseya.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Kaseya — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Kaseya's Products

View all 2 CNAs →

Top CWEs