Veeam is a specialist vendor in backup, replication, and disaster-recovery software deployed across enterprise data centers and hybrid-cloud environments, where its products sit at a critical juncture between production workloads and recovery infrastructure. Vulnerabilities affecting the vendor skew strongly toward critical severity and have an elevated tendency toward confirmed in-the-wild exploitation and public exploit availability, reflecting the high-value nature of backup and orchestration targets. The exposure concentrates in flagship products such as Backup & Replication, Veeam One, and Recovery Orchestrator, and recurs through weakness classes including deserialization of untrusted data, improper access control, sensitive-information exposure, and cross-site scripting—patterns that reflect both the integration-heavy architecture of enterprise backup platforms and their role as trusted conduits for administrative access. Defenders should prioritize inventory and patching of Veeam deployments, especially internet-reachable instances, and treat recovery-tier compromises as high-impact; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Veeam over time
Signals from CVEs in this vendor scope (75 CVEs).
75 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-40711CRITICAL A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE). | Sep 7, 2024 | 9.8 | 97 | YES | YES |
CVE-2023-27532HIGH Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead to gaining access to the backu | Mar 10, 2023 | 7.5 | 93 | YES | NO |
CVE-2020-10915CRITICAL This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587. Authentication is not required to exploit this vulnera | Apr 22, 2020 | 9.8 | 80 | NO | YES |
CVE-2022-26501CRITICAL Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2). | Mar 17, 2022 | 9.8 | 73 | YES | NO |
CVE-2022-26500HIGH Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API functions that allows attackers | Mar 17, 2022 | 8.8 | 69 | YES | NO |
CVE-2020-10914CRITICAL This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587. Authentication is not required to exploit this vulnera | Apr 22, 2020 | 9.8 | 60 | NO | YES |
CVE-2020-15419HIGH This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0.0.750_20200415. Authentication is not required to exploit t | Jul 28, 2020 | 7.5 | 50 | NO | NO |
CVE-2025-23120HIGH A vulnerability allowing remote code execution (RCE) for domain users. | Mar 20, 2025 | 8.8 | 42 | NO | NO |
CVE-2024-29849CRITICAL Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface. | May 22, 2024 | 9.8 | 41 | NO | NO |
CVE-2023-38547CRITICAL A vulnerability in Veeam ONE allows an unauthenticated user to gain information about the SQL server connection Veeam ONE uses to access its configuration database. This may lead t | Nov 7, 2023 | 9.8 | 41 | NO | NO |
Signals from CVEs in this vendor scope (75 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Veeam.
Media articles that mention a CVE ID that affects a product developed by Veeam — matched by CVE ID, not by vendor name.